← Home

@omnigraph/thrift

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dotansimhaurigoardatankamilkisielatheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@creditkarma/thrift-parser AI (dependencies): Legitimate thrift parsing dependency used across graphql-mesh ecosystem; stable for this package. ai
dependencies unvetted-dep:@graphql-mesh/transport-thrift AI (dependencies): Same graphql-mesh monorepo sibling package from the same publisher; stable for this package. ai
npm-metadata no-description AI (npm-metadata): Monorepo package; missing description is a consistent pattern across the graphql-mesh workspace, not a malware signal. ai
phantom-deps phantom-dep:thrift AI (phantom-deps): thrift is a declared runtime dep used indirectly via @creditkarma/thrift-server-core; phantom-dep heuristic is a false positive here. ai

Versions (showing 51 of 95)

View all versions
Version Deps Published
0.9.40 9 / 0
0.9.39 9 / 0
0.9.38 9 / 0
0.9.37 9 / 0
0.9.36 9 / 0
0.9.35 9 / 0
0.9.34 9 / 0
0.9.33 9 / 0
0.9.32 9 / 0
0.9.31 9 / 0
0.9.27 9 / 0
0.9.26 9 / 0
0.9.25 9 / 0
0.9.24 9 / 0
0.9.23 9 / 0
0.9.22 9 / 0
0.9.21 9 / 0
0.9.20 9 / 0
0.9.19 9 / 0
0.9.18 9 / 0
0.9.17 9 / 0
0.9.16 9 / 0
0.9.15 9 / 0
0.9.14 9 / 0
0.9.13 9 / 0
0.9.12 9 / 0
0.9.11 9 / 0
0.9.10 9 / 0
0.9.9 9 / 0
0.9.8 9 / 0
0.9.7 9 / 0
0.9.6 9 / 0
0.9.5 9 / 0
0.9.4 9 / 0
0.9.3 9 / 0
0.9.2 9 / 0
0.9.1 9 / 0
0.9.0 9 / 0
0.8.21 9 / 0
0.8.20 9 / 0
0.8.19 9 / 0
0.8.18 9 / 0
0.8.17 9 / 0
0.8.16 9 / 0
0.8.15 9 / 0
0.8.14 9 / 0
0.8.13 9 / 0
0.8.12 9 / 0
0.8.11 9 / 0
0.8.10 9 / 0
0.8.9 9 / 0

v0.9.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.