@owf/eudi-attestation-schema
SDK for creating, signing, and validating attestation schema metadata (SchemaMeta) per EUDI TS11 Catalogue of Attestations
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; gitHead absence likely reflects CI pipeline change, not tampering. | ai | |
| phantom-deps | phantom-dep:@owf/crypto | AI (phantom-deps): Same-org workspace dep; re-exported or used transitively. Stable FP for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@owf/identity-common | AI (phantom-deps): Same-org workspace dep; re-exported or used transitively. Stable FP for this monorepo package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Likely used via re-export or config; common pattern in monorepo packages. | ai | |
| dependencies | unvetted-dep:@owf/crypto | AI (dependencies): Sibling package from the same OpenWallet Foundation Labs monorepo; same publisher and provenance chain. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 0.3.2 | 3 / 1 | |
| 0.3.1 | 3 / 1 | |
| 0.3.0 | 3 / 1 | |
| 0.2.0 | 3 / 0 | |
| 0.1.0 | 3 / 0 |
v0.3.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v0.3.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.