← Home

@nuxtjs/seo

10
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

harlan_zw

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): simple-git-hooks is a dev-tool git hook installer; it is a no-op when run outside a git repo (i.e., as an npm dependency). ai
phantom-deps phantom-dep:nuxt-seo-utils AI (phantom-deps): Nuxt module deps are registered via config, not direct imports; stable pattern for this package. ai
phantom-deps phantom-dep:nuxt-site-config AI (phantom-deps): Same Nuxt module config pattern; not a real phantom dep. ai
phantom-deps phantom-dep:nuxt-link-checker AI (phantom-deps): Same Nuxt module config pattern; not a real phantom dep. ai

Versions (showing 10 of 10)

Version Deps Published
5.1.3 9 / 19
5.1.2 9 / 19
5.1.1 9 / 19
5.1.0 9 / 19
5.0.2 9 / 17
5.0.1 9 / 17
4.0.2 8 / 23
4.0.1 8 / 23
3.4.0 8 / 16
3.3.0 8 / 16

v5.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: simple-git-hooks

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.