← Home

@mysten/seal

19
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

ebmifahayespaul-mystenrushrs

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): MystenLabs migrated to GitHub Actions CI publishing with SLSA attestation; not an account compromise. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects new SDK under MystenLabs org; CI-published with SLSA provenance confirms legitimacy. ai

Versions (showing 19 of 19)

Version Deps Published
1.3.3 3 / 4
1.3.2 3 / 4
1.3.1 3 / 4
1.3.0 3 / 4
1.2.4 3 / 4
1.2.3 3 / 4
1.2.2 3 / 4
1.2.1 3 / 4
1.2.0 3 / 4
1.1.3 3 / 4
1.1.2 3 / 4
1.1.1 3 / 5
1.1.0 3 / 5
1.0.1 3 / 5
1.0.0 3 / 5
0.10.0 4 / 5
0.9.6 4 / 5
0.9.5 4 / 5
0.9.4 4 / 5

v1.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.