← Home

@onflow/fcl

17
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

han210dapperjdapper_labsjeffreydoyleharry.ethchasefleminggregorgggturbolent_ffjribbinkbthailenialexsansisyphussmilingkan-flow-foundationmanny.ffmichael_flowlmcmze

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@onflow/sdk AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:events AI (phantom-deps): Transitive dependency; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:sha3 AI (phantom-deps): Transitive dependency; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:cross-fetch AI (phantom-deps): Transitive dependency; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@onflow/types AI (phantom-deps): Same-org package; convention-loaded in monorepo structure. ai
phantom-deps phantom-dep:@walletconnect/types AI (phantom-deps): Transitive dependency; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@onflow/util-actor AI (phantom-deps): Same-org dependency; monorepo pattern stable for this package. ai
phantom-deps phantom-dep:@onflow/rlp AI (phantom-deps): Same-org dependency; monorepo pattern stable for this package. ai
phantom-deps phantom-dep:@onflow/util-template AI (phantom-deps): Same-org dependency; monorepo pattern stable for this package. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped package loaded by convention; stable pattern. ai
phantom-deps phantom-dep:@onflow/interaction AI (phantom-deps): Same-org dependency; monorepo pattern stable for this package. ai
phantom-deps phantom-dep:@onflow/util-logger AI (phantom-deps): Same-org dependency; monorepo pattern stable for this package. ai
phantom-deps phantom-dep:@onflow/util-semver AI (phantom-deps): Same-org dependency; monorepo pattern stable for this package. ai
phantom-deps phantom-dep:@onflow/util-address AI (phantom-deps): Same-org dependency; monorepo pattern stable for this package. ai

Versions (showing 17 of 17)

Version Deps Published
1.21.10 21 / 10
1.21.9 21 / 10
1.21.8 21 / 10
1.21.7 21 / 10
1.21.1 21 / 10
1.21.0 21 / 10
1.20.6 21 / 10
1.20.5 21 / 10
1.20.4 21 / 10
1.20.3 21 / 10
1.20.2 21 / 10
1.20.1 21 / 10
1.20.0 21 / 10
1.19.0 21 / 10
1.18.0 21 / 10
1.17.0 21 / 10
1.10.0 17 / 10

v1.21.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.21.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.21.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.21.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.