← Home

@malloydata/malloy

21
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

malloy-lang-usergmadenscullinmtoy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:url AI (phantom-deps): Likely used indirectly via bundled/transpiled build; established package with no malicious behavior. ai
phantom-deps phantom-dep:blueimp-md5 AI (phantom-deps): Likely used indirectly via bundled/transpiled build; established package with no malicious behavior. ai
npm-metadata url-dep:@malloydata/malloy AI (npm-metadata): Self-referential file: dep, likely monorepo build artifact, not a real risk. ai
phantom-deps phantom-dep:@malloydata/malloy AI (phantom-deps): Same-scope self-reference, benign. ai
dependencies unvetted-dep:antlr4ts AI (dependencies): antlr4ts is the standard ANTLR4 TypeScript runtime; expected dependency for a query language compiler like Malloy. ai
phantom-deps phantom-dep:assert AI (phantom-deps): Referenced in config/test files only; stable false positive for this package. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Config-only reference; stable false positive for this package. ai
phantom-deps phantom-dep:jest-diff AI (phantom-deps): Config-only reference; stable false positive for this package. ai

Versions (showing 21 of 421)

Version Deps Published
0.0.22 5 / 4
0.0.21 5 / 3
0.0.20 5 / 3
0.0.19 5 / 3
0.0.18 5 / 3
0.0.17 5 / 3
0.0.16 5 / 3
0.0.15 5 / 3
0.0.14 5 / 3
0.0.13 5 / 3
0.0.12 5 / 3
0.0.11 5 / 3
0.0.10 5 / 3
0.0.9 5 / 3
0.0.8 5 / 3
0.0.7 5 / 3
0.0.6 5 / 3
0.0.5 5 / 3
0.0.3 5 / 3
0.0.2 7 / 4
0.0.1 6 / 4

v0.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.