← Home

@quonfig/node

40
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jdwyah

Keywords

quonfigfeature-flagsconfigremote-configfeature-toggle

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD with SLSA provenance; expected and more secure pattern. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped SDK package unrelated to zod; Levenshtein match is coincidental. ai

Versions (showing 40 of 40)

Version Deps Published
1.2.0 2 / 9
1.1.1 2 / 9
1.1.0 2 / 9
1.0.0 2 / 9
0.0.37 2 / 9
0.0.36 2 / 9
0.0.35 2 / 9
0.0.34 2 / 9
0.0.33 2 / 9
0.0.32 2 / 9
0.0.31 2 / 9
0.0.30 2 / 9
0.0.29 2 / 9
0.0.28 2 / 9
0.0.27 2 / 9
0.0.26 2 / 9
0.0.25 2 / 8
0.0.24 2 / 8
0.0.23 2 / 9
0.0.22 2 / 9
0.0.20 2 / 9
0.0.19 2 / 9
0.0.18 2 / 9
0.0.17 2 / 9
0.0.16 2 / 9
0.0.15 2 / 9
0.0.14 2 / 7
0.0.13 2 / 7
0.0.12 2 / 7
0.0.11 2 / 7
0.0.10 2 / 7
0.0.9 2 / 7
0.0.8 2 / 7
0.0.7 2 / 7
0.0.6 2 / 7
0.0.5 2 / 7
0.0.4 2 / 7
0.0.3 2 / 7
0.0.2 2 / 7
0.0.1 2 / 7

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.