← Home

@relaycast/types

79
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

Verified SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

khaliqgantwillwashburn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from khaliqgant to GitHub Actions as part of legitimate CI/CD automation setup, backed by SLSA provenance attestation linking artifacts to the repo. ai
bogus-package bogus-package AI (bogus-package): A scoped types-only package with no deps, no keywords, and no description is normal for a TypeScript types sub-package in a monorepo. ai

Versions (showing 79 of 79)

Version Deps Published
6.3.0 1 / 0
6.2.0 1 / 0
6.1.0 1 / 0
6.0.5 1 / 0
6.0.4 1 / 0
6.0.3 1 / 0
6.0.2 1 / 0
6.0.1 1 / 0
6.0.0 1 / 0
5.1.1 1 / 0
5.1.0 1 / 0
5.0.12 1 / 0
5.0.11 1 / 0
5.0.10 1 / 0
5.0.9 1 / 0
5.0.8 1 / 0
5.0.7 1 / 0
5.0.6 1 / 0
5.0.5 1 / 0
5.0.4 1 / 0
5.0.3 1 / 0
5.0.2 1 / 0
5.0.1 1 / 0
5.0.0 1 / 0
4.2.0 1 / 0
4.1.6 1 / 0
4.1.5 1 / 0
4.1.4 1 / 0
4.1.3 1 / 0
4.1.2 1 / 0
4.1.1 1 / 0
4.1.0 1 / 0
4.0.0 1 / 0
3.1.1 1 / 0
3.1.0 1 / 0
3.0.0 1 / 0
2.6.0 1 / 0
2.5.1 1 / 0
2.5.0 1 / 0
2.4.0 1 / 0
2.3.0 1 / 0
2.2.0 1 / 0
2.1.0 1 / 0
2.0.0 1 / 0
1.2.0 1 / 0
1.1.7 1 / 0
1.1.6 1 / 0
1.1.5 1 / 0
1.1.4 1 / 0
1.1.3 1 / 0
1.1.2 1 / 0
1.1.1 1 / 0
1.1.0 1 / 0
1.0.0 1 / 0
0.7.0 1 / 0
0.6.0 1 / 0
0.5.3 1 / 0
0.5.2 1 / 0
0.5.1 1 / 0
0.5.0 1 / 0
0.4.2 1 / 0
0.4.1 1 / 0
0.4.0 1 / 0
0.3.4 1 / 0
0.3.3 1 / 0
0.3.2 1 / 0
0.3.1 1 / 0
0.3.0 1 / 0
0.2.5 1 / 0
0.2.4 0 / 0
0.2.3 0 / 0
0.2.2 0 / 0
0.2.1 0 / 0
0.2.0 0 / 0
0.1.4 0 / 0
0.1.3 0 / 0
0.1.2 0 / 0
0.1.1 0 / 0
0.1.0 0 / 0

v6.3.0

1 finding
INFO Has verified SLSA provenance attestation provenance

Published via CI/CD with a Sigstore attestation that VERIFIED against the pinned Sigstore trust root (predicate: https://slsa.dev/provenance/v1, issuer: https://token.actions.githubusercontent.com). The attestation's sha512 subject digest matches the tarball bytes we streamed, so it describes this exact artifact. This is the strongest supply chain integrity signal.

v6.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.