← Home

@oscarpalmer/abydon

[MIT licensed](LICENSE), natch :wink:

15
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

oscarpalmer

Keywords

componentsdomlibraryliteralsreactivesignaltemplatevanilla

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): Deps are sibling packages from the same trusted publisher, not third-party additions. ai
dependencies unvetted-dep:@oscarpalmer/sentinel AI (dependencies): Same-author companion package, consistent with other oscarpalmer packages. ai
bogus-package bogus-package AI (bogus-package): Sparse README is a style choice, not spam; publisher has strong track record. ai
dependencies unvetted-dep:@oscarpalmer/mora AI (dependencies): Same-author sibling package; consistent with the rest of the @oscarpalmer/* ecosystem. ai
dependencies unvetted-dep:@oscarpalmer/toretto AI (dependencies): Same-author sibling package; consistent with the rest of the @oscarpalmer/* ecosystem. ai
provenance no-provenance AI (provenance): Author consistently publishes without provenance; no other risk signals present. ai

Versions (showing 15 of 15)

Version Deps Published
0.21.0 3 / 9
0.20.0 3 / 9
0.19.0 3 / 9
0.17.0 3 / 9
0.16.0 3 / 11
0.15.0 3 / 13
0.14.0 3 / 13
0.13.0 3 / 14
0.11.0 3 / 5
0.10.0 3 / 5
0.5.0 2 / 4
0.4.0 1 / 4
0.3.0 1 / 4
0.2.0 0 / 4
0.1.0 0 / 0

v0.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.