@openrewrite/rewrite
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Large active project with frequent releases; occasional gitHead gaps are a CI config issue, not a supply-chain indicator. | ai | |
| phantom-deps | phantom-dep:dedent | AI (phantom-deps): dedent is declared in dependencies and likely used in dist output; phantom-dep heuristic false positive. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): commander/typescript/tmp-promise are established packages added for the RPC server feature; not suspicious for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from individual (zieka) to GitHub Actions CI publisher is expected for a maturing project; SLSA attestation confirms integrity. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env into child_process spawn options is standard; not exfiltration. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is a type-only dep used at compile time; not imported at runtime. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Resolves optional prettier peer dep by path; documented plugin-loader pattern. | ai |
Versions (showing 100 of 157)
| Version | Deps | Published |
|---|---|---|
| 8.87.7 | 12 / 9 | |
| 8.87.6 | 12 / 9 | |
| 8.87.5 | 12 / 9 | |
| 8.87.4 | 12 / 9 | |
| 8.87.3 | 12 / 9 | |
| 8.87.2 | 12 / 9 | |
| 8.87.1 | 12 / 9 | |
| 8.87.0 | 12 / 9 | |
| 8.86.5 | 12 / 9 | |
| 8.86.4 | 12 / 9 | |
| 8.86.2 | 12 / 9 | |
| 8.86.1 | 12 / 9 | |
| 8.86.0 | 12 / 9 | |
| 8.85.7 | 12 / 9 | |
| 8.85.6 | 12 / 9 | |
| 8.85.5 | 12 / 9 | |
| 8.85.4 | 12 / 9 | |
| 8.85.3 | 12 / 9 | |
| 8.85.2 | 12 / 9 | |
| 8.85.1 | 12 / 9 | |
| 8.85.0 | 12 / 9 | |
| 8.84.9 | 12 / 9 | |
| 8.84.8 | 12 / 9 | |
| 8.84.7 | 12 / 9 | |
| 8.84.6 | 12 / 9 | |
| 8.84.5 | 12 / 9 | |
| 8.84.4 | 12 / 9 | |
| 8.84.3 | 12 / 9 | |
| 8.84.2 | 12 / 9 | |
| 8.84.1 | 12 / 9 | |
| 8.84.0 | 12 / 9 | |
| 8.83.7 | 12 / 9 | |
| 8.83.6 | 12 / 9 | |
| 8.83.5 | 12 / 9 | |
| 8.83.4 | 12 / 9 | |
| 8.83.3 | 12 / 9 | |
| 8.83.2 | 12 / 9 | |
| 8.83.1 | 12 / 9 | |
| 8.83.0 | 12 / 9 | |
| 8.82.1 | 12 / 8 | |
| 8.82.0 | 12 / 8 | |
| 8.81.17 | 12 / 8 | |
| 8.81.16 | 12 / 8 | |
| 8.81.15 | 12 / 8 | |
| 8.81.14 | 12 / 8 | |
| 8.81.13 | 12 / 8 | |
| 8.81.12 | 12 / 8 | |
| 8.81.11 | 12 / 8 | |
| 8.81.10 | 12 / 8 | |
| 8.81.9 | 12 / 8 | |
| 8.81.8 | 12 / 8 | |
| 8.81.7 | 12 / 8 | |
| 8.81.6 | 12 / 8 | |
| 8.81.5 | 12 / 8 | |
| 8.81.4 | 12 / 8 | |
| 8.81.3 | 12 / 8 | |
| 8.81.2 | 12 / 8 | |
| 8.81.1 | 12 / 8 | |
| 8.81.0 | 12 / 8 | |
| 8.80.1 | 12 / 8 | |
| 8.80.0 | 12 / 8 | |
| 8.79.6 | 12 / 8 | |
| 8.79.5 | 12 / 8 | |
| 8.79.4 | 12 / 8 | |
| 8.79.3 | 12 / 8 | |
| 8.79.2 | 12 / 8 | |
| 8.79.1 | 12 / 8 | |
| 8.79.0 | 12 / 8 | |
| 8.78.6 | 12 / 8 | |
| 8.78.5 | 12 / 8 | |
| 8.78.4 | 12 / 8 | |
| 8.78.3 | 12 / 8 | |
| 8.78.2 | 12 / 8 | |
| 8.78.1 | 12 / 8 | |
| 8.78.0 | 12 / 8 | |
| 8.77.2 | 12 / 8 | |
| 8.77.1 | 12 / 8 | |
| 8.77.0 | 12 / 8 | |
| 8.76.4 | 12 / 8 | |
| 8.76.3 | 12 / 8 | |
| 8.76.2 | 12 / 8 | |
| 8.76.1 | 12 / 8 | |
| 8.76.0 | 12 / 8 | |
| 8.75.11 | 12 / 8 | |
| 8.75.10 | 12 / 8 | |
| 8.75.9 | 12 / 8 | |
| 8.75.8 | 12 / 8 | |
| 8.75.7 | 12 / 8 | |
| 8.75.6 | 12 / 8 | |
| 8.75.5 | 12 / 8 | |
| 8.75.4 | 12 / 8 | |
| 8.75.3 | 12 / 12 | |
| 8.75.2 | 12 / 12 | |
| 8.75.1 | 12 / 12 | |
| 8.75.0 | 12 / 12 | |
| 8.74.3 | 12 / 12 | |
| 8.74.2 | 12 / 12 | |
| 8.74.1 | 12 / 12 | |
| 8.74.0 | 12 / 12 | |
| 8.73.2 | 12 / 12 |
v8.87.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.87.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.86.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.85.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.77.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.77.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.76.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.76.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.76.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.76.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.76.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.75.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.74.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.74.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.74.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.74.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.73.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.