@mittwald/api-code-generator
Common code base used by `@mittwald/api-client-*` package.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation and no material changes vs prior version; automated CI/CD release from established mittwald org. | ai | |
| dependencies | unvetted-dep:yieldable-json | AI (dependencies): Stable dependency in a well-established package; no malware indicators. | ai | |
| dependencies | unvetted-dep:@types/clone-deep | AI (dependencies): Type-only dev dependency; no runtime risk. | ai | |
| dependencies | unvetted-dep:@types/yieldable-json | AI (dependencies): Type-only dependency; no runtime risk. | ai | |
| dependencies | unvetted-dep:openapi-schema-validator | AI (dependencies): Widely used OpenAPI tooling dependency; no malware indicators. | ai | |
| phantom-deps | phantom-dep:@types/yieldable-json | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): Referenced in oclif config block, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/verror | AI (phantom-deps): @types/* loaded by convention, not direct import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zod-validation-error | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-plugins | AI (phantom-deps): Referenced in oclif config block, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/js-yaml | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/prettier | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/invariant | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/clone-deep | AI (phantom-deps): @types/* loaded by convention; stable false positive. | ai |
Versions (showing 87 of 87)
| Version | Deps | Published |
|---|---|---|
| 4.428.0 | 28 / 17 | |
| 4.426.0 | 28 / 17 | |
| 4.425.0 | 28 / 17 | |
| 4.424.0 | 28 / 17 | |
| 4.423.0 | 28 / 17 | |
| 4.422.0 | 28 / 17 | |
| 4.421.0 | 28 / 17 | |
| 4.420.0 | 28 / 17 | |
| 4.419.0 | 28 / 17 | |
| 4.418.0 | 28 / 17 | |
| 4.417.0 | 28 / 17 | |
| 4.416.0 | 28 / 17 | |
| 4.415.0 | 28 / 17 | |
| 4.414.0 | 28 / 17 | |
| 4.413.0 | 28 / 17 | |
| 4.412.0 | 28 / 17 | |
| 4.411.0 | 28 / 17 | |
| 4.410.0 | 28 / 17 | |
| 4.409.0 | 28 / 17 | |
| 4.408.0 | 28 / 17 | |
| 4.407.0 | 28 / 17 | |
| 4.406.0 | 28 / 17 | |
| 4.405.1 | 28 / 17 | |
| 4.405.0 | 28 / 17 | |
| 4.404.0 | 28 / 17 | |
| 4.403.0 | 28 / 17 | |
| 4.402.0 | 28 / 17 | |
| 4.401.0 | 28 / 17 | |
| 4.400.0 | 28 / 17 | |
| 4.399.0 | 28 / 17 | |
| 4.398.0 | 28 / 17 | |
| 4.397.0 | 28 / 17 | |
| 4.396.0 | 28 / 17 | |
| 4.395.0 | 28 / 17 | |
| 4.394.0 | 28 / 17 | |
| 4.393.0 | 28 / 17 | |
| 4.392.0 | 28 / 17 | |
| 4.391.0 | 28 / 17 | |
| 4.390.0 | 28 / 17 | |
| 4.389.0 | 28 / 17 | |
| 4.388.0 | 28 / 17 | |
| 4.387.0 | 28 / 17 | |
| 4.386.0 | 28 / 17 | |
| 4.385.0 | 28 / 17 | |
| 4.384.0 | 28 / 17 | |
| 4.383.0 | 28 / 17 | |
| 4.382.0 | 28 / 17 | |
| 4.380.0 | 28 / 17 | |
| 4.379.0 | 28 / 17 | |
| 4.378.0 | 28 / 17 | |
| 4.377.0 | 28 / 17 | |
| 4.376.0 | 28 / 17 | |
| 4.375.0 | 28 / 17 | |
| 4.374.0 | 28 / 17 | |
| 4.373.0 | 28 / 17 | |
| 4.372.0 | 28 / 17 | |
| 4.371.0 | 28 / 17 | |
| 4.370.0 | 28 / 17 | |
| 4.369.0 | 28 / 17 | |
| 4.368.0 | 28 / 17 | |
| 4.367.0 | 28 / 17 | |
| 4.366.0 | 28 / 17 | |
| 4.364.1 | 28 / 17 | |
| 4.364.0 | 28 / 17 | |
| 4.363.0 | 28 / 17 | |
| 4.362.0 | 28 / 17 | |
| 4.361.0 | 28 / 17 | |
| 4.360.1 | 28 / 17 | |
| 4.360.0 | 28 / 17 | |
| 4.359.0 | 28 / 17 | |
| 4.358.0 | 28 / 17 | |
| 4.357.0 | 28 / 17 | |
| 4.356.1 | 28 / 17 | |
| 4.356.0 | 28 / 17 | |
| 4.355.0 | 28 / 17 | |
| 4.354.0 | 28 / 17 | |
| 4.339.0 | 28 / 17 | |
| 4.338.1 | 28 / 17 | |
| 4.338.0 | 28 / 17 | |
| 4.129.2 | 28 / 17 | |
| 4.115.1 | 28 / 17 | |
| 4.81.1 | 28 / 17 | |
| 4.60.0 | 28 / 17 | |
| 4.47.1 | 28 / 17 | |
| 4.44.4 | 28 / 17 | |
| 4.44.3 | 28 / 17 | |
| 4.14.1 | 28 / 17 |
v4.428.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.426.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.425.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.424.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.423.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.422.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.421.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.420.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.419.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.418.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.417.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.416.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.415.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.414.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.413.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.412.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.411.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.410.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.409.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.408.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.407.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.406.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.405.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.405.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.404.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.403.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.402.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.401.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.400.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.399.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.129.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.115.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.81.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.60.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.47.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.44.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.14.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.