← Home

@pob/root

root package

23
Versions
ISC
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

churpeau

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Expected artifact of manual→CI/CD provenance transition, not a regression. ai
publish-pattern new-deps-added AI (publish-pattern): picomatch is a well-known, widely-used glob library. ai
dependencies unvetted-dep:@pob/pretty-pkg AI (dependencies): Same @pob org package, consistent with this monorepo's internal dependency pattern. ai
phantom-deps phantom-dep:pob-dependencies AI (phantom-deps): Referenced in config files as documented; stable false positive for this tooling package. ai
semgrep semgrep:env-spread AI (semgrep): env-spread is used to pass environment to execSync subprocess — standard pattern, not exfiltration. ai
phantom-deps phantom-dep:conventional-changelog-writer AI (phantom-deps): Used indirectly via config; stable false positive for this tooling package. ai
phantom-deps phantom-dep:conventional-commits-parser AI (phantom-deps): Used indirectly via config; stable false positive for this tooling package. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require resolves a hardcoded 'prettier' module path, not user-controlled input. ai
typosquat typosquat.levenshtein:got AI (typosquat): Scoped @pob/ package with 2281 days history; Levenshtein match to 'got' is a false positive. ai

Versions (showing 23 of 23)

Version Deps Published
25.0.0 13 / 0
24.1.0 13 / 0
24.0.0 13 / 0
23.2.0 13 / 0
23.1.0 13 / 0
23.0.0 13 / 0
22.4.0 13 / 0
22.3.0 13 / 0
22.2.0 13 / 0
22.1.0 13 / 0
22.0.0 13 / 0
21.0.0 13 / 0
20.4.2 14 / 0
20.4.1 14 / 0
20.3.0 14 / 0
20.2.2 14 / 0
20.2.1 14 / 0
20.2.0 14 / 0
20.1.0 14 / 0
20.0.3 14 / 0
20.0.2 14 / 0
20.0.0 14 / 0
19.8.0 17 / 0

v25.0.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.