@moltzap/protocol
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation; missing gitHead is a minor metadata gap, not a supply chain risk here. | ai |
Versions (showing 51 of 84)
| Version | Deps | Published |
|---|---|---|
| 2026.724.2 | 4 / 7 | |
| 2026.724.1 | 4 / 8 | |
| 2026.724.0 | 4 / 8 | |
| 2026.721.1 | 4 / 8 | |
| 2026.721.0 | 4 / 8 | |
| 2026.718.0 | 4 / 8 | |
| 2026.717.0 | 4 / 8 | |
| 2026.529.0 | 5 / 8 | |
| 2026.528.0 | 5 / 8 | |
| 2026.526.0 | 5 / 8 | |
| 2026.525.0 | 5 / 8 | |
| 2026.524.1 | 5 / 7 | |
| 2026.524.0 | 5 / 7 | |
| 2026.523.0 | 5 / 7 | |
| 2026.520.1 | 5 / 7 | |
| 2026.520.0 | 5 / 7 | |
| 2026.519.2 | 5 / 7 | |
| 2026.519.1 | 5 / 7 | |
| 2026.519.0 | 5 / 7 | |
| 2026.518.0 | 5 / 7 | |
| 2026.511.3 | 5 / 6 | |
| 2026.511.2 | 5 / 6 | |
| 2026.511.1 | 5 / 6 | |
| 2026.511.0 | 5 / 6 | |
| 2026.509.7 | 5 / 6 | |
| 2026.509.6 | 5 / 6 | |
| 2026.509.5 | 5 / 6 | |
| 2026.509.4 | 5 / 6 | |
| 2026.509.3 | 5 / 6 | |
| 2026.509.2 | 5 / 6 | |
| 2026.509.1 | 5 / 6 | |
| 2026.509.0 | 5 / 6 | |
| 2026.508.4 | 5 / 6 | |
| 2026.508.3 | 5 / 6 | |
| 2026.508.2 | 5 / 6 | |
| 2026.508.1 | 5 / 6 | |
| 2026.508.0 | 5 / 6 | |
| 2026.507.1 | 5 / 6 | |
| 2026.507.0 | 5 / 6 | |
| 2026.506.3 | 5 / 6 | |
| 2026.506.2 | 5 / 6 | |
| 2026.506.1 | 5 / 6 | |
| 2026.506.0 | 5 / 6 | |
| 2026.505.5 | 5 / 6 | |
| 2026.505.4 | 5 / 6 | |
| 2026.505.3 | 5 / 6 | |
| 2026.505.2 | 5 / 6 | |
| 2026.505.1 | 5 / 6 | |
| 2026.505.0 | 5 / 6 | |
| 2026.504.3 | 5 / 6 | |
| 2026.504.2 | 5 / 6 |
v2026.724.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.724.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.724.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.721.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.721.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.718.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.717.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.529.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.