@putitoutthere/piot-fixture-zzz-js-bundled-aarch64-apple-darwin
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): Platform-specific prebuilt binary package published via CI with SLSA provenance; bundled binary is the package's entire purpose. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Auto-generated platform-specific package; sparse metadata is consistent across all 268 versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Platform-specific binary fixture package; sparse metadata and tiny payload are expected for this package type. | ai |
Versions (showing 100 of 362)
v0.0.1779478117
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779476610
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779476492
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779476247
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779476081
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779475833
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779475363
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779475346
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779474730
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779474552
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779474486
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779474405
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779473944
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779473890
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779473822
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779473441
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779472970
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779472963
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779466137
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779465599
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779465268
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779465186
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779456817
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779456369
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779455857
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779455773
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779455278
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779272205
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779271585
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779229712
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779229192
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779129932
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779129502
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779129055
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779128602
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779127838
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779127361
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779124917
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779124816
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779124484
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779124024
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779123905
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779123380
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779122781
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779122546
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779122142
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779119579
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779119019
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779117827
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779115952
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779115796
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779115356
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779115253
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779114547
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1779054260
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778773568
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778761989
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778761489
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778761377
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778760024
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778759931
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778758840
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778758627
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778758520
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778756710
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778756330
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778755059
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778719866
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778719499
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778719317
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778719300
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778719013
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778718925
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778718531
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778718032
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778717450
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778717259
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778716898
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778716890
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778716609
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778716542
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778716167
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778715346
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778714816
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778714523
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778714462
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778714081
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778713776
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778712823
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778712433
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778711929
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778711771
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778711586
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778710640
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778709977
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778709610
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778709392
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778709271
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778709245
2 findingsPackage contains compiled binaries that could be backdoors: • piot-fixture-zzz
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.1778709158
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.