@platformatic/kafka
Modern and performant client for Apache Kafka
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Active Kafka client library; large file additions reflect feature growth, not injected code, given SLSA provenance. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party @platformatic/* packages consistent with the project's own ecosystem expansion. | ai | |
| provenance | no-provenance | AI (provenance): Established Platformatic package; lack of provenance is consistent across all versions and not a risk signal here. | ai | |
| dependencies | unvetted-dep:@platformatic/wasm-utils | AI (dependencies): First-party @platformatic sibling package; same org as the publisher. | ai | |
| dependencies | unvetted-dep:@platformatic/dynamic-buffer | AI (dependencies): First-party @platformatic sibling package; same org as the publisher. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 2.8.0 | 9 / 34 | |
| 2.7.0 | 8 / 34 | |
| 2.6.1 | 8 / 34 | |
| 2.6.0 | 8 / 34 | |
| 2.5.0 | 8 / 34 | |
| 2.4.0 | 8 / 34 | |
| 2.3.1 | 8 / 34 | |
| 2.3.0 | 8 / 34 | |
| 2.2.3 | 8 / 34 | |
| 2.2.2 | 8 / 34 | |
| 2.1.0 | 8 / 34 | |
| 2.0.1 | 8 / 34 | |
| 2.0.0 | 8 / 34 | |
| 1.34.0 | 8 / 35 | |
| 1.33.2 | 8 / 35 | |
| 1.33.0 | 8 / 35 | |
| 1.32.1 | 8 / 35 | |
| 1.32.0 | 8 / 35 | |
| 1.31.0 | 8 / 35 | |
| 1.30.0 | 8 / 35 | |
| 1.29.0 | 8 / 35 | |
| 1.28.0 | 8 / 35 | |
| 1.27.0 | 7 / 36 | |
| 1.26.0 | 5 / 33 | |
| 1.25.0 | 5 / 33 | |
| 1.24.0 | 5 / 33 | |
| 1.23.0 | 5 / 33 | |
| 1.22.0 | 5 / 25 | |
| 1.21.0 | 5 / 23 | |
| 1.3.0 | 7 / 18 | |
| 1.2.0 | 7 / 18 | |
| 1.1.0 | 6 / 19 | |
| 1.0.0 | 6 / 19 |
v2.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.