← Home

@osdk/foundry-sdk-generator

94
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sauravsanjpalantirericandersonericjeney-palantir

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@osdk/shared.net.errors AI (phantom-deps): Same-org monorepo peer dep pattern; stable for @osdk/* packages. ai
phantom-deps phantom-dep:@osdk/client.api AI (phantom-deps): Same-org monorepo peer dep pattern; stable for @osdk/* packages. ai
phantom-deps phantom-dep:@osdk/shared.net AI (phantom-deps): Same-org monorepo peer dep pattern; stable for @osdk/* packages. ai
phantom-deps phantom-dep:@osdk/shared.client AI (phantom-deps): Same-org monorepo peer dep pattern; stable for @osdk/* packages. ai
phantom-deps phantom-dep:@osdk/shared.net.fetch AI (phantom-deps): Same-org monorepo peer dep pattern; stable for @osdk/* packages. ai
npm-metadata no-description AI (npm-metadata): Palantir monorepo package; empty description is a consistent pattern across their SDK packages, not a malware indicator. ai
phantom-deps phantom-dep:@osdk/api AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for this monorepo package. ai
phantom-deps phantom-dep:@osdk/client AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for this monorepo package. ai
phantom-deps phantom-dep:@osdk/client.unstable AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for this monorepo package. ai
phantom-deps phantom-dep:@osdk/foundry.thirdpartyapplications AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for this monorepo package. ai

Versions (showing 94 of 94)

Version Deps Published
2.51.0 18 / 8
2.50.0 18 / 8
2.49.0 18 / 8
2.48.0 18 / 8
2.47.0 18 / 8
2.46.0 18 / 8
2.45.0 18 / 8
2.44.0 18 / 8
2.43.0 18 / 8
2.42.0 18 / 8
2.41.0 18 / 8
2.40.0 18 / 8
2.39.0 18 / 8
2.38.0 18 / 8
2.37.0 18 / 8
2.36.0 18 / 8
2.35.0 18 / 8
2.34.0 18 / 8
2.33.0 18 / 8
2.32.0 18 / 8
2.31.0 18 / 8
2.30.0 18 / 8
2.29.0 18 / 8
2.28.0 18 / 8
2.27.0 18 / 8
2.26.0 18 / 8
2.25.0 18 / 8
2.24.0 18 / 8
2.23.0 18 / 8
2.22.0 18 / 8
2.21.0 18 / 8
2.20.0 18 / 8
2.19.0 18 / 8
2.17.0 18 / 8
2.16.0 18 / 8
2.15.0 18 / 8
2.14.0 18 / 8
2.13.0 18 / 7
2.12.0 18 / 7
2.11.0 18 / 7
2.10.0 18 / 7
2.9.0 18 / 7
2.8.0 18 / 7
2.7.8 15 / 10
2.7.7 15 / 10
2.7.6 15 / 10
2.7.5 15 / 10
2.7.4 15 / 10
2.7.3 15 / 10
2.7.2 15 / 10
2.7.1 15 / 10
2.7.0 15 / 10
2.6.3 15 / 10
2.6.2 15 / 10
2.6.1 15 / 10
2.6.0 15 / 10
2.5.7 15 / 10
2.5.6 15 / 10
2.5.5 15 / 10
2.5.4 15 / 10
2.5.3 15 / 10
2.5.2 15 / 10
2.5.1 15 / 10
2.5.0 15 / 10
2.4.2 15 / 10
2.4.1 15 / 10
2.4.0 15 / 10
2.3.4 15 / 10
2.3.3 15 / 10
2.3.2 15 / 10
2.3.1 15 / 10
2.3.0 15 / 10
2.2.1 15 / 10
2.2.0 15 / 10
2.1.5 15 / 9
2.1.4 15 / 9
2.1.3 15 / 9
2.1.2 15 / 9
2.1.1 15 / 9
2.1.0 15 / 9
2.0.13 18 / 11
2.0.12 18 / 11
2.0.11 18 / 11
2.0.10 18 / 11
2.0.9 18 / 11
2.0.8 18 / 11
2.0.7 18 / 10
2.0.6 18 / 10
2.0.5 18 / 10
2.0.4 18 / 10
2.0.3 18 / 10
2.0.2 18 / 10
1.3.18 19 / 8
1.3.17 20 / 8

v2.51.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.50.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.