@nestia/fetcher
Fetcher library of Nestia SDK
22
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
samchon
Keywords
nestiafetchersdk
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): CI pipeline change explains missing gitHead; SLSA provenance attestation provides equivalent supply chain integrity. | ai | |
| phantom-deps | phantom-dep:@typia/interface | AI (phantom-deps): Type-only dependency used in config/type declarations; not directly imported at runtime is expected for interface packages. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from samchon to GitHub Actions reflects CI/CD automation of the samchon/nestia repo; SLSA attestation confirms legitimate pipeline. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Major version bump (v10) after dormancy is consistent with active development; SLSA provenance confirms legitimate publish. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 12.1.0 | 2 / 3 | |
| 12.0.0 | 2 / 3 | |
| 11.3.4 | 2 / 10 | |
| 11.3.3 | 2 / 10 | |
| 11.3.2 | 2 / 10 | |
| 11.3.1 | 2 / 10 | |
| 11.3.0 | 2 / 10 | |
| 11.2.1 | 2 / 10 | |
| 11.2.0 | 2 / 10 | |
| 11.1.0 | 2 / 10 | |
| 11.0.2 | 2 / 3 | |
| 11.0.1 | 2 / 3 | |
| 11.0.0 | 2 / 3 | |
| 10.0.2 | 1 / 5 | |
| 10.0.1 | 1 / 5 | |
| 10.0.0 | 1 / 5 | |
| 9.1.1 | 1 / 5 | |
| 9.1.0 | 1 / 5 | |
| 9.0.3 | 1 / 5 | |
| 9.0.2 | 1 / 5 | |
| 9.0.1 | 1 / 5 | |
| 9.0.0 | 1 / 5 |
v12.1.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.