← Home

@prairielearn/flash

Adds support for flash messages to Express applications.

12
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nwalters512mwest1066

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): CI-published monorepo package; maintainer listing churn without content change. ai
provenance missing-githead AI (provenance): Diff shows no material changes; likely CI metadata quirk, not environment compromise. ai
npm-metadata no-description AI (npm-metadata): Internal monorepo package, consistently missing description across versions. ai
provenance publisher-changed AI (provenance): PrairieLearn monorepo migrated to GitHub Actions CI publishing with SLSA attestation; publisher change is expected and verifiable. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects monorepo restructuring/CI migration, not account takeover; SLSA provenance confirms legitimate publish. ai
phantom-deps phantom-dep:@types/express AI (phantom-deps): @types/express is a type-only dependency used for Express type augmentation; not directly imported at runtime. ai

Versions (showing 12 of 12)

Version Deps Published
3.0.8 2 / 5
3.0.7 2 / 5
3.0.6 2 / 5
3.0.5 2 / 5
3.0.4 2 / 8
3.0.3 2 / 9
3.0.2 2 / 7
3.0.1 2 / 7
3.0.0 2 / 7
2.0.27 2 / 7
2.0.26 2 / 6
2.0.25 2 / 6

v3.0.8

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.