← Home

@revisium/endpoint

Revisium is a tool (UI/API) inspired by JSON (JSON Schema) and Git, designed to provide a flexible and low-level headless CMS solution.

9
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

revisium-io

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@nestjs/apollo AI (phantom-deps): NestJS framework module loaded by convention, not direct import; stable false positive for this package. ai
phantom-deps phantom-dep:@nestjs/graphql AI (phantom-deps): NestJS framework module loaded by convention, not direct import; stable false positive for this package. ai
phantom-deps phantom-dep:ioredis AI (phantom-deps): Redis client referenced in config files; common NestJS pattern, stable false positive. ai
phantom-deps phantom-dep:@nestjs/schedule AI (phantom-deps): NestJS module loaded by convention in config; stable false positive. ai
phantom-deps phantom-dep:reflect-metadata AI (phantom-deps): Known NestJS implicit runtime dependency; stable false positive for this package. ai
phantom-deps phantom-dep:@pothos/plugin-add-graphql AI (phantom-deps): GraphQL plugin referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:@nestjs/event-emitter AI (phantom-deps): NestJS module loaded by convention in config; stable false positive. ai
phantom-deps phantom-dep:@types/pg AI (phantom-deps): Type-only package loaded by convention in NestJS/Prisma projects; stable false positive. ai

Versions (showing 9 of 9)

Version Deps Published
2.6.0 31 / 30
2.5.1 31 / 29
2.4.0 33 / 29
2.3.0 33 / 29
2.2.0 33 / 27
2.1.1 30 / 26
2.1.0 30 / 26
2.0.1 28 / 26
2.0.0 28 / 26

v2.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.