← Home

@octokit/app

5
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

octokitbot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:hapi AI (typosquat): @octokit/app is a canonical scoped package under the official Octokit org; levenshtein match against 'hapi' is a false positive with no plausible typosquat scenario. ai
typosquat typosquat.levenshtein:pg AI (typosquat): @octokit/app is a canonical scoped package under the official Octokit org; levenshtein match against 'pg' is a false positive with no plausible typosquat scenario. ai
typosquat typosquat.levenshtein:yup AI (typosquat): @octokit/app is a canonical scoped package under the official Octokit org; levenshtein match against 'yup' is a false positive with no plausible typosquat scenario. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): @octokit/app is a canonical scoped package under the official Octokit org; levenshtein match against 'ajv' is a false positive with no plausible typosquat scenario. ai
dependencies unvetted-dep:@octokit/webhooks AI (dependencies): First-party Octokit sibling package; expected runtime dependency for a GitHub Apps toolkit published by the same org. ai
dependencies unvetted-dep:@octokit/oauth-app AI (dependencies): First-party Octokit sibling package; expected runtime dependency for a GitHub Apps toolkit published by the same org. ai
dependencies unvetted-dep:@octokit/auth-unauthenticated AI (dependencies): First-party Octokit sibling package; expected runtime dependency for a GitHub Apps toolkit published by the same org. ai

Versions (showing 5 of 5)

Version Deps Published
16.1.2 7 / 12
16.1.1 7 / 12
16.1.0 7 / 12
16.0.1 7 / 12
16.0.0 7 / 12

v16.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.