← Home

@malloydata/db-duckdb

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

malloy-lang-usergmadenscullinmtoy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@malloydata/duckdb-wasm AI (dependencies): First-party sibling package within same org/monorepo, not a real supply-chain risk. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is confirmed legitimate by SLSA/Sigstore provenance attestation on this and subsequent releases. ai
publish-pattern new-deps-added AI (publish-pattern): @duckdb/node-api is the official DuckDB Node API; addition is consistent with this DuckDB connector package's purpose. ai
publish-pattern dormant-publish AI (publish-pattern): Package is part of active malloydata monorepo with 1502+ versions; dormancy flag is a false positive for this sub-package. ai
dependencies unvetted-dep:@duckdb/node-api AI (dependencies): @duckdb/node-api is the official DuckDB Node.js API; expected dependency for this DuckDB connector package. ai
bogus-package bogus-package AI (bogus-package): Scoped org package in a large monorepo; sparse README and no keywords are expected for internal packages. ai
provenance no-provenance AI (provenance): Established package with 1500+ versions; no provenance is consistent across all prior releases. ai

Versions (showing 100 of 249)

Version Deps Published
0.0.426 6 / 0
0.0.412 6 / 0
0.0.396 6 / 0
0.0.395 6 / 0
0.0.393 6 / 0
0.0.387 6 / 0
0.0.385 6 / 0
0.0.384 6 / 0
0.0.381 6 / 0
0.0.379 6 / 0
0.0.376 6 / 0
0.0.375 6 / 0
0.0.374 6 / 0
0.0.373 6 / 0
0.0.370 6 / 0
0.0.368 6 / 0
0.0.361 6 / 0
0.0.342 6 / 0
0.0.336 6 / 0
0.0.334 6 / 0
0.0.332 6 / 0
0.0.331 6 / 0
0.0.330 6 / 0
0.0.329 6 / 0
0.0.328 6 / 0
0.0.327 6 / 0
0.0.326 6 / 0
0.0.325 6 / 0
0.0.324 6 / 0
0.0.323 6 / 0
0.0.322 6 / 0
0.0.321 6 / 0
0.0.320 6 / 0
0.0.319 6 / 0
0.0.318 6 / 0
0.0.317 6 / 0
0.0.316 6 / 0
0.0.315 6 / 0
0.0.314 6 / 0
0.0.313 6 / 0
0.0.312 6 / 0
0.0.311 6 / 0
0.0.310 6 / 0
0.0.309 6 / 0
0.0.308 6 / 0
0.0.307 6 / 0
0.0.306 6 / 0
0.0.305 6 / 0
0.0.304 6 / 0
0.0.303 6 / 0
0.0.302 6 / 0
0.0.301 6 / 0
0.0.300 6 / 0
0.0.299 6 / 0
0.0.298 6 / 0
0.0.297 6 / 0
0.0.296 6 / 0
0.0.295 6 / 0
0.0.294 6 / 0
0.0.293 6 / 0
0.0.292 6 / 0
0.0.291 6 / 0
0.0.290 6 / 0
0.0.289 6 / 0
0.0.288 6 / 0
0.0.287 6 / 0
0.0.286 6 / 0
0.0.285 6 / 0
0.0.284 6 / 0
0.0.283 6 / 0
0.0.282 6 / 0
0.0.281 6 / 0
0.0.280 6 / 0
0.0.279 6 / 0
0.0.278 6 / 0
0.0.277 6 / 0
0.0.276 6 / 0
0.0.275 6 / 0
0.0.274 6 / 0
0.0.273 6 / 0
0.0.272 6 / 0
0.0.271 6 / 0
0.0.270 6 / 0
0.0.269 6 / 0
0.0.268 6 / 0
0.0.267 6 / 0
0.0.266 6 / 0
0.0.265 6 / 0
0.0.264 6 / 0
0.0.263 6 / 0
0.0.262 6 / 0
0.0.261 6 / 0
0.0.260 6 / 0
0.0.259 6 / 0
0.0.258 6 / 0
0.0.257 6 / 0
0.0.256 6 / 0
0.0.255 6 / 0
0.0.254 6 / 0
0.0.253 6 / 0
Showing 100 of 249 Next page →

v0.0.426

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.412

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.269

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.268

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.267

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.266

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.265

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.264

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.263

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.262

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.261

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.260

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.259

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.258

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.257

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.256

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.255

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.254

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.253

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.