← Home

@pnpm/deps.compliance.commands

pnpm commands for audit, licenses, and sbom

26
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

pnpmuserzkochan

Keywords

pnpmpnpm11auditlicensessbom

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party @pnpm-scoped packages; consistent with pnpm monorepo release pattern. ai
dependencies unvetted-dep:@pnpm/config.writer AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/lockfile.walker AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/installing.commands AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/deps.compliance.sbom AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/deps.compliance.audit AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/cli.common-cli-options-help AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:render-help AI (dependencies): Legitimate pnpm monorepo dependency; publisher has strong track record. ai
dependencies unvetted-dep:@pnpm/cli.meta AI (dependencies): Internal @pnpm monorepo package; stable pattern across versions. ai
dependencies unvetted-dep:@pnpm/config.reader AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/cli.utils AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/store.path AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/cli.command AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/deps.compliance.license-scanner AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/deps.compliance.license-resolver AI (dependencies): Internal @pnpm monorepo package. ai
dependencies unvetted-dep:@pnpm/workspace.project-manifest-reader AI (dependencies): Internal @pnpm monorepo package. ai
phantom-deps phantom-dep:memoize AI (phantom-deps): Declared in package.json dependencies; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@pnpm/workspace.project-manifest-reader AI (phantom-deps): Internal @pnpm monorepo package; same-org phantom-dep false positive. ai
dependencies unvetted-dep:@zkochan/table AI (dependencies): Known pnpm ecosystem dependency; no risk signal. ai

Versions (showing 26 of 26)

Version Deps Published
1101.3.2 31 / 17
1101.3.1 31 / 17
1101.3.0 31 / 17
1101.2.8 31 / 18
1101.2.7 31 / 17
1101.2.6 31 / 17
1101.2.5 31 / 17
1101.2.4 31 / 17
1101.2.3 31 / 17
1101.2.2 31 / 17
1101.2.1 31 / 17
1101.2.0 31 / 17
1101.1.11 29 / 17
1101.1.10 29 / 17
1101.1.9 29 / 17
1101.1.8 29 / 17
1101.1.7 29 / 17
1101.1.6 29 / 17
1101.1.5 29 / 17
1101.1.3 29 / 17
1101.1.2 28 / 17
1101.1.1 28 / 17
1101.0.1 26 / 15
1101.0.0 26 / 15
1100.0.0 26 / 15
1000.0.0 26 / 13

v1101.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1101.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1100.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1000.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.