@peerbit/proxy-window
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Established publisher with 221 approvals; missing gitHead is a minor CI environment change, not a malicious indicator. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): peerbit is the first-party package from the same dao.xyz org; not a suspicious third-party dep. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Version diff shows no material changes; publisher has prior approvals and package is part of the active peerbit monorepo. | ai | |
| dependencies | unvetted-dep:peerbit | AI (dependencies): First-party peerbit monorepo package from same dao-xyz org; stable false positive. | ai | |
| dependencies | unvetted-dep:@peerbit/proxy | AI (dependencies): First-party peerbit monorepo package from same dao-xyz org; stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Consistent across all peerbit/* packages; not a malice indicator for this ecosystem. | ai |
Versions (showing 51 of 94)
| Version | Deps | Published |
|---|---|---|
| 3.1.14 | 2 / 1 | |
| 3.1.13 | 2 / 1 | |
| 3.1.12 | 2 / 1 | |
| 3.1.11 | 2 / 1 | |
| 3.1.10 | 2 / 1 | |
| 3.1.9 | 2 / 1 | |
| 3.1.8 | 2 / 1 | |
| 3.1.7 | 2 / 1 | |
| 3.1.6 | 2 / 1 | |
| 3.1.5 | 2 / 1 | |
| 3.1.4 | 2 / 1 | |
| 3.1.3 | 2 / 1 | |
| 3.1.2 | 2 / 1 | |
| 3.1.1 | 2 / 1 | |
| 3.1.0 | 2 / 1 | |
| 3.0.118 | 2 / 1 | |
| 3.0.117 | 2 / 1 | |
| 3.0.115 | 1 / 1 | |
| 3.0.114 | 1 / 1 | |
| 3.0.113 | 1 / 1 | |
| 3.0.112 | 1 / 1 | |
| 3.0.110 | 1 / 1 | |
| 3.0.109 | 1 / 1 | |
| 3.0.108 | 1 / 1 | |
| 3.0.107 | 1 / 1 | |
| 3.0.106 | 1 / 1 | |
| 3.0.105 | 1 / 1 | |
| 3.0.104 | 1 / 1 | |
| 3.0.103 | 1 / 1 | |
| 3.0.102 | 1 / 1 | |
| 3.0.101 | 1 / 1 | |
| 3.0.100 | 1 / 1 | |
| 3.0.98 | 1 / 1 | |
| 3.0.97 | 1 / 1 | |
| 3.0.96 | 1 / 1 | |
| 3.0.95 | 1 / 1 | |
| 3.0.94 | 1 / 1 | |
| 3.0.93 | 1 / 1 | |
| 3.0.92 | 1 / 1 | |
| 3.0.91 | 1 / 1 | |
| 3.0.90 | 1 / 1 | |
| 3.0.89 | 1 / 1 | |
| 3.0.88 | 1 / 1 | |
| 3.0.87 | 1 / 1 | |
| 3.0.86 | 1 / 1 | |
| 3.0.85 | 1 / 1 | |
| 3.0.84 | 1 / 1 | |
| 3.0.83 | 1 / 1 | |
| 3.0.82 | 1 / 1 | |
| 3.0.81 | 1 / 1 | |
| 3.0.80 | 1 / 1 |
v3.0.92
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.91
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.90
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.89
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.88
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.87
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.86
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.85
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.84
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.83
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.82
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.81
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.80
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.