@naturalcycles/nodejs-lib
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Used in secrets-decrypt CLI for decrypting encrypted secrets; legitimate cryptographic use. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads only SECRET_* prefixed env vars for secrets management; expected pattern for this library. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a TypeScript runtime helper; implicit dependency, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/yargs | AI (phantom-deps): @types/* packages are type-only; not directly imported at runtime. | ai | |
| phantom-deps | phantom-dep:@types/jsonwebtoken | AI (phantom-deps): @types/* packages are type-only; not directly imported at runtime. | ai |
Versions (showing 100 of 182)
| Version | Deps | Published |
|---|---|---|
| 15.119.0 | 11 / 2 | |
| 15.118.0 | 11 / 2 | |
| 15.117.0 | 11 / 2 | |
| 15.116.3 | 11 / 2 | |
| 15.116.2 | 11 / 2 | |
| 15.116.1 | 11 / 2 | |
| 15.116.0 | 11 / 2 | |
| 15.115.1 | 10 / 2 | |
| 15.115.0 | 10 / 2 | |
| 15.114.0 | 10 / 2 | |
| 15.113.0 | 12 / 2 | |
| 15.112.0 | 12 / 2 | |
| 15.111.0 | 12 / 2 | |
| 15.110.0 | 12 / 2 | |
| 15.109.0 | 12 / 2 | |
| 15.108.0 | 12 / 2 | |
| 15.107.4 | 12 / 2 | |
| 15.107.3 | 12 / 2 | |
| 15.107.2 | 12 / 2 | |
| 15.107.1 | 12 / 2 | |
| 15.107.0 | 12 / 2 | |
| 15.106.3 | 12 / 2 | |
| 15.106.2 | 12 / 2 | |
| 15.106.1 | 12 / 2 | |
| 15.106.0 | 12 / 2 | |
| 15.105.0 | 12 / 2 | |
| 15.104.0 | 12 / 2 | |
| 15.103.0 | 12 / 2 | |
| 15.102.0 | 12 / 2 | |
| 15.101.0 | 12 / 2 | |
| 15.100.0 | 12 / 2 | |
| 15.99.0 | 12 / 2 | |
| 15.98.0 | 13 / 2 | |
| 15.97.5 | 14 / 2 | |
| 15.97.4 | 14 / 2 | |
| 15.97.3 | 14 / 2 | |
| 15.97.2 | 14 / 2 | |
| 15.97.1 | 14 / 2 | |
| 15.97.0 | 14 / 2 | |
| 15.96.1 | 14 / 2 | |
| 15.96.0 | 14 / 2 | |
| 15.95.0 | 13 / 2 | |
| 15.94.0 | 13 / 2 | |
| 15.93.0 | 13 / 2 | |
| 15.92.1 | 13 / 2 | |
| 15.92.0 | 13 / 2 | |
| 15.91.0 | 13 / 2 | |
| 15.90.2 | 13 / 2 | |
| 15.90.1 | 13 / 1 | |
| 15.90.0 | 13 / 1 | |
| 15.89.1 | 14 / 1 | |
| 15.89.0 | 14 / 1 | |
| 15.88.0 | 14 / 1 | |
| 15.87.0 | 14 / 1 | |
| 15.86.0 | 14 / 1 | |
| 15.85.0 | 14 / 1 | |
| 15.84.0 | 14 / 1 | |
| 15.83.0 | 14 / 1 | |
| 15.82.1 | 14 / 1 | |
| 15.82.0 | 14 / 1 | |
| 15.81.1 | 14 / 1 | |
| 15.81.0 | 14 / 1 | |
| 15.80.2 | 14 / 1 | |
| 15.80.1 | 14 / 1 | |
| 15.80.0 | 14 / 1 | |
| 15.79.0 | 14 / 1 | |
| 15.78.2 | 14 / 1 | |
| 15.78.1 | 14 / 1 | |
| 15.78.0 | 14 / 1 | |
| 15.77.1 | 14 / 1 | |
| 15.77.0 | 14 / 1 | |
| 15.76.0 | 14 / 1 | |
| 15.75.0 | 14 / 1 | |
| 15.74.1 | 14 / 1 | |
| 15.74.0 | 14 / 1 | |
| 15.73.0 | 14 / 1 | |
| 15.72.2 | 14 / 1 | |
| 15.72.1 | 14 / 1 | |
| 15.72.0 | 14 / 1 | |
| 15.71.0 | 14 / 1 | |
| 15.70.1 | 15 / 2 | |
| 15.70.0 | 15 / 2 | |
| 15.69.1 | 15 / 2 | |
| 15.69.0 | 15 / 2 | |
| 15.68.0 | 15 / 2 | |
| 15.67.1 | 15 / 2 | |
| 15.67.0 | 15 / 2 | |
| 15.66.0 | 15 / 2 | |
| 15.65.3 | 15 / 2 | |
| 15.65.2 | 15 / 2 | |
| 15.65.1 | 15 / 2 | |
| 15.65.0 | 15 / 2 | |
| 15.64.0 | 15 / 2 | |
| 15.63.1 | 15 / 2 | |
| 15.63.0 | 15 / 2 | |
| 15.62.1 | 15 / 2 | |
| 15.62.0 | 15 / 2 | |
| 15.61.1 | 15 / 2 | |
| 15.61.0 | 15 / 2 | |
| 15.60.0 | 15 / 2 |
v15.119.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.118.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.117.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.116.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.116.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.116.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.116.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.115.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.115.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.114.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.