@mittwald/api-code-generator
Common code base used by `@mittwald/api-client-*` package.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation and no material changes vs prior version; automated CI/CD release from established mittwald org. | ai | |
| dependencies | unvetted-dep:yieldable-json | AI (dependencies): Stable dependency in a well-established package; no malware indicators. | ai | |
| dependencies | unvetted-dep:@types/clone-deep | AI (dependencies): Type-only dev dependency; no runtime risk. | ai | |
| dependencies | unvetted-dep:@types/yieldable-json | AI (dependencies): Type-only dependency; no runtime risk. | ai | |
| dependencies | unvetted-dep:openapi-schema-validator | AI (dependencies): Widely used OpenAPI tooling dependency; no malware indicators. | ai | |
| phantom-deps | phantom-dep:@types/yieldable-json | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): Referenced in oclif config block, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/verror | AI (phantom-deps): @types/* loaded by convention, not direct import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zod-validation-error | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-plugins | AI (phantom-deps): Referenced in oclif config block, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/js-yaml | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/prettier | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/invariant | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/clone-deep | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 4.380.0 | 28 / 17 | |
| 4.379.0 | 28 / 17 | |
| 4.378.0 | 28 / 17 | |
| 4.377.0 | 28 / 17 | |
| 4.376.0 | 28 / 17 | |
| 4.375.0 | 28 / 17 | |
| 4.374.0 | 28 / 17 | |
| 4.373.0 | 28 / 17 | |
| 4.372.0 | 28 / 17 | |
| 4.371.0 | 28 / 17 | |
| 4.370.0 | 28 / 17 | |
| 4.369.0 | 28 / 17 | |
| 4.368.0 | 28 / 17 | |
| 4.367.0 | 28 / 17 | |
| 4.366.0 | 28 / 17 | |
| 4.364.1 | 28 / 17 | |
| 4.364.0 | 28 / 17 | |
| 4.363.0 | 28 / 17 | |
| 4.362.0 | 28 / 17 | |
| 4.361.0 | 28 / 17 | |
| 4.360.1 | 28 / 17 | |
| 4.360.0 | 28 / 17 | |
| 4.359.0 | 28 / 17 | |
| 4.358.0 | 28 / 17 | |
| 4.357.0 | 28 / 17 | |
| 4.356.1 | 28 / 17 | |
| 4.356.0 | 28 / 17 | |
| 4.355.0 | 28 / 17 | |
| 4.354.0 | 28 / 17 | |
| 4.339.0 | 28 / 17 | |
| 4.338.1 | 28 / 17 | |
| 4.338.0 | 28 / 17 |
v4.380.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.379.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.378.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.377.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.376.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.375.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.374.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.373.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.372.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.371.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.370.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.369.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.368.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.367.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.366.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.364.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.364.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.363.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.362.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.361.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.360.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.360.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.359.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.358.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.357.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.356.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.356.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.355.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.339.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.338.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.338.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.