← Home

@peac/protocol

PEAC protocol implementation - receipt issuance and verification

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

peacprotocol

Keywords

peacpeacprotocolinteraction-recordssigned-recordsreceiptsoriginaryverificationissuancereceipt-verificationpolicy-binding

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; legitimate pipeline migration. ai
provenance missing-githead AI (provenance): GitHub Actions CI publish via SLSA attestation replaces gitHead as provenance signal. ai
source-diff source-size-tripled AI (source-diff): Size increase due to newly bundled dist files (CJS/ESM + sourcemaps) added in this version. ai
provenance no-provenance AI (provenance): Established package with clean history; lack of Sigstore attestation is a process gap, not a security threat. ai

Versions (showing 51 of 52)

View all versions
Version Deps Published
0.16.3 5 / 6
0.16.2 5 / 6
0.16.1 5 / 6
0.16.0 5 / 6
0.15.3 5 / 6
0.15.2 5 / 6
0.15.1 5 / 6
0.15.0 5 / 6
0.14.5 5 / 6
0.14.4 5 / 6
0.14.3 5 / 6
0.14.2 5 / 6
0.14.1 5 / 6
0.14.0 5 / 6
0.13.4 5 / 6
0.13.3 5 / 6
0.13.2 5 / 6
0.13.1 5 / 6
0.13.0 5 / 4
0.12.14 5 / 4
0.12.13 5 / 4
0.12.12 5 / 4
0.12.11 5 / 4
0.12.10 5 / 4
0.12.9 5 / 4
0.12.8 5 / 4
0.12.7 5 / 4
0.12.6 5 / 4
0.12.5 5 / 4
0.12.4 5 / 4
0.12.3 5 / 4
0.12.2 5 / 4
0.12.1 5 / 4
0.12.0 5 / 4
0.11.3 5 / 4
0.11.2 5 / 4
0.11.1 5 / 4
0.11.0 5 / 4
0.10.14 5 / 4
0.10.13 5 / 4
0.10.12 5 / 4
0.10.11 5 / 4
0.10.10 5 / 4
0.10.9 5 / 3
0.10.8 6 / 3
0.10.7 6 / 3
0.10.6 6 / 3
0.10.5 6 / 3
0.10.4 6 / 3
0.10.0 6 / 3
0.9.31 6 / 3

v0.16.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.