@promptbook/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:eval-usage | AI (semgrep): eval() used in a sandboxed script-execution loop with a TODO to replace; consistent with the package's scripting-engine purpose. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function() used for browser-environment detection idiom; standard pattern in cross-platform JS libraries. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @promptbook/core; Levenshtein match to 'cors' is a false positive with no brand confusion. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 0.104.0 | 11 / 0 | |
| 0.103.0 | 11 / 0 | |
| 0.101.0 | 8 / 0 | |
| 0.100.2 | 8 / 0 | |
| 0.100.1 | 8 / 0 | |
| 0.100.0 | 8 / 0 | |
| 0.98.0 | 9 / 0 | |
| 0.95.0 | 9 / 0 | |
| 0.94.0 | 9 / 0 | |
| 0.93.0 | 9 / 0 | |
| 0.92.0 | 9 / 0 |
v0.104.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.103.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.101.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.100.2
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.100.1
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.100.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.95.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.0
2 findingsPackage name '@promptbook/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.