@owf/cose
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD publishing pipeline explains rapid successive publishes for this org's monorepo. | ai | |
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation via Sigstore; missing gitHead is a non-issue when full provenance is present. | ai | |
| phantom-deps | phantom-dep:cbor-x | AI (phantom-deps): Monorepo workspace package; same pattern as other phantom-dep findings. | ai | |
| phantom-deps | phantom-dep:zod-validation-error | AI (phantom-deps): Monorepo workspace package; same pattern as other phantom-dep findings. | ai | |
| phantom-deps | phantom-dep:@owf/identity-common | AI (phantom-deps): Same-org workspace dependency; expected in monorepo setup. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Monorepo workspace package; deps declared at workspace level, not directly imported in dist. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): COSE (cryptographic standard) package under @owf org; name similarity to 'cors' is coincidental. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 0.3.2 | 4 / 6 | |
| 0.3.1 | 4 / 6 | |
| 0.3.0 | 4 / 6 | |
| 0.2.0 | 4 / 5 | |
| 0.1.0 | 4 / 5 |
v0.3.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v0.3.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.