@notion-headless-cms/notion-orm
Notion ORM layer for notion-headless-cms — implements DataSource<T>. Consumed via CLI-generated nhc-schema.ts.
52
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
kjfsm
Keywords
notionnotion-apiheadless-cmscmsdatasourceormtypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@notion-headless-cms/markdown-html | AI (dependencies): Same-org sibling package; consistent across all versions of this monorepo package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a same-monorepo sibling package replacing a prior dep; not an external unknown package. | ai | |
| dependencies | unvetted-dep:notion-to-md | AI (dependencies): notion-to-md is a well-established package for Notion block-to-Markdown conversion; its use is appropriate and expected for a Notion ORM layer package. | ai | |
| provenance | no-provenance | AI (provenance): package.json declares provenance:true in publishConfig; likely a CI/tooling gap rather than intentional omission. Low risk for this package. | ai | |
| provenance | slsa-provenance | AI (provenance): Package is consistently published via CI/CD with Sigstore SLSA provenance attestation; this is a stable, positive signal for this monorepo package. | ai |
Versions (showing 52 of 52)
| Version | Deps | Published |
|---|---|---|
| 0.2.13 | 3 / 3 | |
| 0.2.12 | 3 / 3 | |
| 0.2.11 | 3 / 3 | |
| 0.2.10 | 3 / 3 | |
| 0.2.9 | 3 / 3 | |
| 0.2.8 | 3 / 3 | |
| 0.2.7 | 3 / 3 | |
| 0.2.6 | 3 / 3 | |
| 0.2.5 | 3 / 3 | |
| 0.2.4 | 3 / 3 | |
| 0.2.3 | 3 / 3 | |
| 0.2.2 | 3 / 3 | |
| 0.2.1 | 3 / 3 | |
| 0.2.0 | 3 / 3 | |
| 0.1.32 | 3 / 3 | |
| 0.1.31 | 3 / 3 | |
| 0.1.30 | 3 / 3 | |
| 0.1.29 | 3 / 3 | |
| 0.1.28 | 3 / 3 | |
| 0.1.27 | 3 / 3 | |
| 0.1.26 | 3 / 3 | |
| 0.1.25 | 3 / 3 | |
| 0.1.24 | 3 / 3 | |
| 0.1.23 | 3 / 3 | |
| 0.1.22 | 3 / 3 | |
| 0.1.21 | 2 / 3 | |
| 0.1.20 | 2 / 3 | |
| 0.1.19 | 2 / 3 | |
| 0.1.18 | 2 / 3 | |
| 0.1.17 | 2 / 3 | |
| 0.1.16 | 2 / 3 | |
| 0.1.15 | 2 / 3 | |
| 0.1.14 | 2 / 3 | |
| 0.1.13 | 2 / 3 | |
| 0.1.12 | 2 / 3 | |
| 0.1.11 | 2 / 3 | |
| 0.1.10 | 2 / 3 | |
| 0.1.9 | 2 / 3 | |
| 0.1.8 | 2 / 3 | |
| 0.1.7 | 2 / 3 | |
| 0.1.6 | 2 / 3 | |
| 0.1.5 | 2 / 3 | |
| 0.1.4 | 2 / 3 | |
| 0.1.3 | 2 / 3 | |
| 0.1.2 | 2 / 3 | |
| 0.1.1 | 2 / 3 | |
| 0.1.0 | 2 / 2 | |
| 0.0.6 | 2 / 2 | |
| 0.0.5 | 2 / 2 | |
| 0.0.4 | 2 / 2 | |
| 0.0.3 | 2 / 2 | |
| 0.0.2 | 2 / 2 |
v0.2.13
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.12
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.