@platformatic/foundation
Platformatic Foundation
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:eval-usage | AI (semgrep): Intentional eval for dynamic ESM import to avoid Turbopack static analysis; documented in source comment. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Standard module-loader pattern in a foundation library; not arbitrary user input. | ai |
Versions (showing 51 of 93)
| Version | Deps | Published |
|---|---|---|
| 3.63.0 | 16 / 9 | |
| 3.62.5 | 16 / 9 | |
| 3.62.4 | 16 / 9 | |
| 3.62.3 | 16 / 9 | |
| 3.62.2 | 16 / 9 | |
| 3.62.1 | 16 / 9 | |
| 3.62.0 | 16 / 9 | |
| 3.61.1 | 16 / 9 | |
| 3.61.0 | 16 / 9 | |
| 3.60.0 | 16 / 9 | |
| 3.59.0 | 16 / 9 | |
| 3.58.1 | 16 / 9 | |
| 3.58.0 | 16 / 9 | |
| 3.57.0 | 16 / 9 | |
| 3.56.0 | 16 / 9 | |
| 3.55.0 | 16 / 9 | |
| 3.54.0 | 16 / 9 | |
| 3.53.0 | 16 / 9 | |
| 3.52.4 | 16 / 9 | |
| 3.52.3 | 16 / 9 | |
| 3.52.2 | 16 / 9 | |
| 3.52.1 | 16 / 9 | |
| 3.52.0 | 16 / 9 | |
| 3.51.0 | 16 / 9 | |
| 3.50.0 | 16 / 9 | |
| 3.49.1 | 16 / 9 | |
| 3.49.0 | 16 / 9 | |
| 3.48.0 | 16 / 9 | |
| 3.47.0 | 16 / 9 | |
| 3.46.0 | 16 / 9 | |
| 3.45.0 | 16 / 9 | |
| 3.44.0 | 16 / 9 | |
| 3.43.0 | 16 / 9 | |
| 3.42.0 | 16 / 9 | |
| 3.41.0 | 16 / 8 | |
| 3.40.0 | 16 / 8 | |
| 3.39.0 | 16 / 8 | |
| 3.38.1 | 16 / 8 | |
| 3.38.0 | 16 / 8 | |
| 3.37.0 | 16 / 8 | |
| 3.36.0 | 16 / 8 | |
| 3.35.1 | 15 / 8 | |
| 3.35.0 | 15 / 8 | |
| 3.34.1 | 15 / 8 | |
| 3.34.0 | 15 / 8 | |
| 3.33.0 | 15 / 8 | |
| 3.32.0 | 15 / 8 | |
| 3.31.0 | 15 / 8 | |
| 3.30.0 | 15 / 8 | |
| 3.29.1 | 15 / 8 | |
| 3.29.0 | 15 / 8 |
v3.63.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.61.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.61.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.60.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.59.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.58.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.58.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.52.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.52.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.52.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.52.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.51.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.50.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.49.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.49.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.