← Home

@openrewrite/rewrite

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

ziekaknutwannhedennatedannersjunglingmccartneyjkschneider

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Large active project with frequent releases; occasional gitHead gaps are a CI config issue, not a supply-chain indicator. ai
phantom-deps phantom-dep:dedent AI (phantom-deps): dedent is declared in dependencies and likely used in dist output; phantom-dep heuristic false positive. ai
publish-pattern new-deps-added AI (publish-pattern): commander/typescript/tmp-promise are established packages added for the RPC server feature; not suspicious for this package. ai
provenance publisher-changed AI (provenance): Transition from individual (zieka) to GitHub Actions CI publisher is expected for a maturing project; SLSA attestation confirms integrity. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env into child_process spawn options is standard; not exfiltration. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): @types/node is a type-only dep used at compile time; not imported at runtime. ai
semgrep semgrep:dynamic-require AI (semgrep): Resolves optional prettier peer dep by path; documented plugin-loader pattern. ai

Versions (showing 51 of 157)

View all versions
Version Deps Published
8.87.7 12 / 9
8.87.6 12 / 9
8.87.5 12 / 9
8.87.4 12 / 9
8.87.3 12 / 9
8.87.2 12 / 9
8.87.1 12 / 9
8.87.0 12 / 9
8.86.5 12 / 9
8.86.4 12 / 9
8.86.2 12 / 9
8.86.1 12 / 9
8.86.0 12 / 9
8.85.7 12 / 9
8.85.6 12 / 9
8.85.5 12 / 9
8.85.4 12 / 9
8.85.3 12 / 9
8.85.2 12 / 9
8.85.1 12 / 9
8.85.0 12 / 9
8.84.9 12 / 9
8.84.8 12 / 9
8.84.7 12 / 9
8.84.6 12 / 9
8.84.5 12 / 9
8.84.4 12 / 9
8.84.3 12 / 9
8.84.2 12 / 9
8.84.1 12 / 9
8.84.0 12 / 9
8.83.7 12 / 9
8.83.6 12 / 9
8.83.5 12 / 9
8.83.4 12 / 9
8.83.3 12 / 9
8.83.2 12 / 9
8.83.1 12 / 9
8.83.0 12 / 9
8.82.1 12 / 8
8.82.0 12 / 8
8.81.17 12 / 8
8.81.16 12 / 8
8.81.15 12 / 8
8.81.14 12 / 8
8.81.13 12 / 8
8.81.12 12 / 8
8.81.11 12 / 8
8.81.10 12 / 8
8.81.9 12 / 8
8.81.8 12 / 8

v8.87.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.87.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.87.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.87.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.87.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.87.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.87.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.87.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.86.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.86.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.86.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.86.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.86.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.85.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.