@openrewrite/rewrite
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Large active project with frequent releases; occasional gitHead gaps are a CI config issue, not a supply-chain indicator. | ai | |
| phantom-deps | phantom-dep:dedent | AI (phantom-deps): dedent is declared in dependencies and likely used in dist output; phantom-dep heuristic false positive. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): commander/typescript/tmp-promise are established packages added for the RPC server feature; not suspicious for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from individual (zieka) to GitHub Actions CI publisher is expected for a maturing project; SLSA attestation confirms integrity. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env into child_process spawn options is standard; not exfiltration. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is a type-only dep used at compile time; not imported at runtime. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Resolves optional prettier peer dep by path; documented plugin-loader pattern. | ai |
Versions (showing 51 of 157)
| Version | Deps | Published |
|---|---|---|
| 8.87.7 | 12 / 9 | |
| 8.87.6 | 12 / 9 | |
| 8.87.5 | 12 / 9 | |
| 8.87.4 | 12 / 9 | |
| 8.87.3 | 12 / 9 | |
| 8.87.2 | 12 / 9 | |
| 8.87.1 | 12 / 9 | |
| 8.87.0 | 12 / 9 | |
| 8.86.5 | 12 / 9 | |
| 8.86.4 | 12 / 9 | |
| 8.86.2 | 12 / 9 | |
| 8.86.1 | 12 / 9 | |
| 8.86.0 | 12 / 9 | |
| 8.85.7 | 12 / 9 | |
| 8.85.6 | 12 / 9 | |
| 8.85.5 | 12 / 9 | |
| 8.85.4 | 12 / 9 | |
| 8.85.3 | 12 / 9 | |
| 8.85.2 | 12 / 9 | |
| 8.85.1 | 12 / 9 | |
| 8.85.0 | 12 / 9 | |
| 8.84.9 | 12 / 9 | |
| 8.84.8 | 12 / 9 | |
| 8.84.7 | 12 / 9 | |
| 8.84.6 | 12 / 9 | |
| 8.84.5 | 12 / 9 | |
| 8.84.4 | 12 / 9 | |
| 8.84.3 | 12 / 9 | |
| 8.84.2 | 12 / 9 | |
| 8.84.1 | 12 / 9 | |
| 8.84.0 | 12 / 9 | |
| 8.83.7 | 12 / 9 | |
| 8.83.6 | 12 / 9 | |
| 8.83.5 | 12 / 9 | |
| 8.83.4 | 12 / 9 | |
| 8.83.3 | 12 / 9 | |
| 8.83.2 | 12 / 9 | |
| 8.83.1 | 12 / 9 | |
| 8.83.0 | 12 / 9 | |
| 8.82.1 | 12 / 8 | |
| 8.82.0 | 12 / 8 | |
| 8.81.17 | 12 / 8 | |
| 8.81.16 | 12 / 8 | |
| 8.81.15 | 12 / 8 | |
| 8.81.14 | 12 / 8 | |
| 8.81.13 | 12 / 8 | |
| 8.81.12 | 12 / 8 | |
| 8.81.11 | 12 / 8 | |
| 8.81.10 | 12 / 8 | |
| 8.81.9 | 12 / 8 | |
| 8.81.8 | 12 / 8 |
v8.87.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.85.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.