← Home

@peac/adapter-x402

x402 offer/receipt verification, term-matching, and PEAC record mapping

39
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

peacprotocol

Keywords

peacpeacprotocolinteraction-recordssigned-recordsreceiptsoriginaryx402adapterpayment-proofreceipt-extraction

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is confirmed legitimate by SLSA/Sigstore attestation on the same version. ai
provenance missing-githead AI (provenance): CI/CD publish via GitHub Actions with SLSA attestation supersedes gitHead as provenance signal. ai
provenance no-provenance AI (provenance): Low-signal for this package; no other risk indicators present. ai
dependencies unvetted-dep:@peac/crypto AI (dependencies): Internal monorepo sibling package at matching version pin; consistent pattern across all @peac/* releases. ai
dependencies unvetted-dep:@peac/protocol AI (dependencies): Internal monorepo sibling package at matching version pin; consistent pattern across all @peac/* releases. ai

Versions (showing 39 of 39)

Version Deps Published
0.16.3 5 / 3
0.16.2 5 / 3
0.16.1 5 / 3
0.16.0 5 / 3
0.15.3 5 / 3
0.15.2 5 / 3
0.15.1 5 / 3
0.15.0 5 / 3
0.14.5 5 / 3
0.14.4 5 / 3
0.14.3 5 / 3
0.14.2 5 / 3
0.14.1 5 / 3
0.14.0 5 / 3
0.13.4 5 / 3
0.13.3 5 / 3
0.13.2 5 / 3
0.13.1 5 / 3
0.13.0 5 / 3
0.12.14 5 / 3
0.12.13 4 / 3
0.12.12 4 / 3
0.12.11 4 / 3
0.12.10 4 / 3
0.12.9 4 / 3
0.12.8 4 / 3
0.12.7 4 / 3
0.12.6 4 / 3
0.12.5 4 / 3
0.12.4 4 / 3
0.12.3 4 / 3
0.12.2 4 / 3
0.12.1 4 / 3
0.12.0 3 / 3
0.11.3 3 / 3
0.11.2 3 / 3
0.11.1 3 / 3
0.10.6 3 / 3
0.10.5 3 / 3

v0.16.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.