← Home

@open-keystone/fields-content

A block-based content field for KeystoneJS

23
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

open-condo-software

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Consistent across all versions of this package; publisher has clean track record. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation and no material diff vs prior version mitigate dormant-publish risk for this package. ai
phantom-deps phantom-dep:immutable AI (phantom-deps): Phantom-dep heuristic false positive; declared as peer/config dep in this UI field package. ai
phantom-deps phantom-dep:@popperjs/core AI (phantom-deps): Phantom-dep heuristic false positive; referenced in config, not a direct import concern. ai
phantom-deps phantom-dep:get-selection-range AI (phantom-deps): Phantom-dep heuristic false positive; declared dep used transitively in this content field package. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI/CD with Sigstore attestation; stable signal for this publisher. ai

Versions (showing 23 of 23)

Version Deps Published
11.0.27 29 / 1
11.0.26 29 / 1
11.0.25 29 / 1
11.0.24 29 / 1
11.0.23 29 / 1
11.0.22 29 / 1
11.0.21 29 / 1
11.0.20 29 / 1
11.0.19 29 / 1
11.0.18 29 / 1
11.0.17 29 / 1
11.0.16 29 / 1
11.0.13 29 / 1
11.0.12 29 / 1
11.0.11 29 / 1
11.0.8 29 / 1
11.0.6 29 / 1
11.0.5 29 / 1
11.0.4 29 / 1
11.0.3 29 / 1
11.0.2 29 / 1
11.0.1 29 / 1
11.0.0 29 / 1

v11.0.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.