← Home

@mistralai/mistralai-gcp

14
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

nelson.proia.mistralaiaac228mistralai-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): SLSA provenance attestation confirms CI/CD build; publisher change appears to be a legitimate bot account transition for the official Mistral AI org. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers align with official Mistral AI org transition; SLSA attestation corroborates legitimacy. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer rotation consistent with org-level transition; no malicious indicators present. ai
source-diff large-new-source-files AI (source-diff): Major version bump (v1→v2) with SDK refactor explains 236 new files; no obfuscation or suspicious patterns flagged. ai

Versions (showing 14 of 14)

Version Deps Published
2.0.0 2 / 3
1.7.0 2 / 5
1.5.0 1 / 6
1.4.0 1 / 7
1.3.6 1 / 7
1.3.5 1 / 7
1.3.4 1 / 7
1.3.1 1 / 7
1.3.0 1 / 7
1.1.0 1 / 7
1.0.4 1 / 7
1.0.3 1 / 7
1.0.2 1 / 7
1.0.0 1 / 7

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.