@pulumi/pulumi
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@pulumi/query | AI (dependencies): First-party Pulumi package; stable dependency across all @pulumi/pulumi versions. | ai | |
| phantom-deps | phantom-dep:pkg-dir | AI (phantom-deps): Declared but not directly imported; consistent with build/config tooling in this package. | ai | |
| phantom-deps | phantom-dep:@types/tmp | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:package-directory | AI (phantom-deps): package-directory is legitimately declared and used in build/config files; expected for SDK packages. | ai | |
| phantom-deps | phantom-dep:@types/google-protobuf | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:@types/semver | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:picomatch | AI (phantom-deps): picomatch is legitimately declared and used in build/config files; expected for SDK packages. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is used to load optional peer deps (ts-node, typescript) by name at runtime — a documented pattern for optional peer dependency loading in this SDK. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): getValue_asB64() is standard protobuf API for accessing binary fields over gRPC; not obfuscation or payload hiding. | ai |
Versions (showing 51 of 140)
| Version | Deps | Published |
|---|---|---|
| 3.245.0 | 27 / 22 | |
| 3.244.0 | 27 / 22 | |
| 3.243.0 | 27 / 22 | |
| 3.242.0 | 27 / 22 | |
| 3.241.0 | 27 / 22 | |
| 3.239.0 | 27 / 22 | |
| 3.238.0 | 27 / 22 | |
| 3.237.0 | 27 / 22 | |
| 3.236.0 | 27 / 22 | |
| 3.235.0 | 27 / 22 | |
| 3.234.0 | 27 / 22 | |
| 3.233.0 | 27 / 22 | |
| 3.232.0 | 27 / 22 | |
| 3.231.0 | 27 / 22 | |
| 3.230.0 | 29 / 22 | |
| 3.229.0 | 29 / 22 | |
| 3.228.0 | 29 / 22 | |
| 3.227.0 | 29 / 22 | |
| 3.226.0 | 29 / 22 | |
| 3.225.1 | 29 / 22 | |
| 3.225.0 | 29 / 22 | |
| 3.224.0 | 28 / 22 | |
| 3.223.0 | 28 / 22 | |
| 3.222.0 | 28 / 22 | |
| 3.221.0 | 28 / 22 | |
| 3.220.0 | 28 / 22 | |
| 3.219.0 | 28 / 22 | |
| 3.218.0 | 28 / 22 | |
| 3.217.1 | 28 / 22 | |
| 3.217.0 | 28 / 22 | |
| 3.216.0 | 28 / 22 | |
| 3.215.0 | 28 / 22 | |
| 3.214.1 | 28 / 22 | |
| 3.214.0 | 28 / 22 | |
| 3.213.0 | 28 / 22 | |
| 3.212.0 | 28 / 22 | |
| 3.211.0 | 28 / 22 | |
| 3.210.0 | 28 / 22 | |
| 3.209.0 | 28 / 23 | |
| 3.208.0 | 28 / 23 | |
| 3.207.0 | 28 / 23 | |
| 3.206.0 | 28 / 23 | |
| 3.205.0 | 28 / 23 | |
| 3.204.0 | 28 / 23 | |
| 3.203.0 | 28 / 23 | |
| 3.202.0 | 28 / 23 | |
| 3.201.0 | 28 / 23 | |
| 3.200.0 | 28 / 23 | |
| 3.199.0 | 28 / 23 | |
| 3.198.0 | 28 / 23 | |
| 3.197.0 | 28 / 23 |
v3.245.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.244.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.243.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.242.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.241.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.239.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.238.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.237.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.236.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.235.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.234.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.233.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.232.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.231.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.230.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.229.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.228.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.227.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.226.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.225.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.225.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.224.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.223.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.222.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.221.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.220.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.219.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.218.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.217.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.217.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.216.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.215.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.214.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.214.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.213.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.212.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.211.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.210.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.209.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.208.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.207.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.206.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.205.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.204.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.203.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.202.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.201.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.