@open-keystone/keystone
The main @open-keystone class & CLI. This is where the magic happens.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation confirms CI/CD publish; dormancy is not indicative of takeover here. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): CLI command-loader reads filenames from a local directory; not user-controlled arbitrary module loading. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 19.4.41 | 31 / 3 | |
| 19.4.40 | 31 / 3 | |
| 19.4.39 | 31 / 3 | |
| 19.4.38 | 31 / 3 | |
| 19.4.37 | 31 / 3 | |
| 19.4.36 | 31 / 3 | |
| 19.4.35 | 31 / 3 | |
| 19.4.34 | 31 / 3 | |
| 19.4.33 | 31 / 3 | |
| 19.4.31 | 31 / 3 | |
| 19.4.30 | 31 / 3 | |
| 19.4.25 | 32 / 4 | |
| 19.4.0 | 30 / 4 |
v19.4.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.