@pulumi/pulumi
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:mockpackage | AI (npm-metadata): Local test fixture in devDependencies, not shipped runtime risk. | ai | |
| phantom-deps | phantom-dep:protobufjs | AI (phantom-deps): Used indirectly via config/codegen, not a real issue. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): V8 intrinsic access in closure serialization internals, not eval of user input. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): Spawns pulumi CLI itself, documented automation API behavior. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Automation API wraps pulumi CLI; expected use of child_process. | ai | |
| dependencies | unvetted-dep:@pulumi/query | AI (dependencies): First-party Pulumi package; stable dependency across all @pulumi/pulumi versions. | ai | |
| phantom-deps | phantom-dep:pkg-dir | AI (phantom-deps): Declared but not directly imported; consistent with build/config tooling in this package. | ai | |
| phantom-deps | phantom-dep:@types/semver | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:@types/google-protobuf | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:package-directory | AI (phantom-deps): package-directory is legitimately declared and used in build/config files; expected for SDK packages. | ai | |
| phantom-deps | phantom-dep:@types/tmp | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:picomatch | AI (phantom-deps): picomatch is legitimately declared and used in build/config files; expected for SDK packages. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is used to load optional peer deps (ts-node, typescript) by name at runtime — a documented pattern for optional peer dependency loading in this SDK. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): getValue_asB64() is standard protobuf API for accessing binary fields over gRPC; not obfuscation or payload hiding. | ai |
Versions (showing 51 of 339)
| Version | Deps | Published |
|---|---|---|
| 3.254.0 | 25 / 18 | |
| 3.253.0 | 25 / 18 | |
| 3.252.0 | 25 / 18 | |
| 3.251.0 | 23 / 18 | |
| 3.250.0 | 23 / 18 | |
| 3.249.0 | 23 / 18 | |
| 3.248.0 | 27 / 22 | |
| 3.247.0 | 27 / 22 | |
| 3.246.0 | 27 / 22 | |
| 3.245.0 | 27 / 22 | |
| 3.244.0 | 27 / 22 | |
| 3.243.0 | 27 / 22 | |
| 3.242.0 | 27 / 22 | |
| 3.241.0 | 27 / 22 | |
| 3.239.0 | 27 / 22 | |
| 3.238.0 | 27 / 22 | |
| 3.237.0 | 27 / 22 | |
| 3.236.0 | 27 / 22 | |
| 3.235.0 | 27 / 22 | |
| 3.234.0 | 27 / 22 | |
| 3.233.0 | 27 / 22 | |
| 3.232.0 | 27 / 22 | |
| 3.231.0 | 27 / 22 | |
| 3.230.0 | 29 / 22 | |
| 3.229.0 | 29 / 22 | |
| 3.228.0 | 29 / 22 | |
| 3.227.0 | 29 / 22 | |
| 3.226.0 | 29 / 22 | |
| 3.225.1 | 29 / 22 | |
| 3.225.0 | 29 / 22 | |
| 3.224.0 | 28 / 22 | |
| 3.223.0 | 28 / 22 | |
| 3.222.0 | 28 / 22 | |
| 3.221.0 | 28 / 22 | |
| 3.220.0 | 28 / 22 | |
| 3.219.0 | 28 / 22 | |
| 3.218.0 | 28 / 22 | |
| 3.217.1 | 28 / 22 | |
| 3.217.0 | 28 / 22 | |
| 3.216.0 | 28 / 22 | |
| 3.215.0 | 28 / 22 | |
| 3.214.1 | 28 / 22 | |
| 3.214.0 | 28 / 22 | |
| 3.213.0 | 28 / 22 | |
| 3.212.0 | 28 / 22 | |
| 3.211.0 | 28 / 22 | |
| 3.210.0 | 28 / 22 | |
| 3.209.0 | 28 / 23 | |
| 3.208.0 | 28 / 23 | |
| 3.207.0 | 28 / 23 | |
| 3.206.0 | 28 / 23 |
v3.254.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.253.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.252.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.251.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.250.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.249.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.