@rhinestone/shared-configs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Versions (showing 51 of 76)
| Version | Deps | Published |
|---|---|---|
| 1.7.5 | 0 / 6 | |
| 1.7.4 | 0 / 6 | |
| 1.7.3 | 0 / 6 | |
| 1.7.2 | 0 / 6 | |
| 1.7.1 | 0 / 6 | |
| 1.7.0 | 0 / 6 | |
| 1.6.15 | 0 / 6 | |
| 1.6.14 | 0 / 6 | |
| 1.6.13 | 0 / 6 | |
| 1.6.12 | 0 / 6 | |
| 1.6.11 | 0 / 6 | |
| 1.6.10 | 0 / 6 | |
| 1.6.9 | 0 / 6 | |
| 1.6.8 | 0 / 6 | |
| 1.6.7 | 0 / 6 | |
| 1.6.6 | 0 / 6 | |
| 1.6.5 | 0 / 6 | |
| 1.6.4 | 0 / 6 | |
| 1.6.3 | 0 / 6 | |
| 1.6.2 | 0 / 6 | |
| 1.6.1 | 0 / 6 | |
| 1.6.0 | 0 / 6 | |
| 1.5.2 | 0 / 6 | |
| 1.5.1 | 0 / 6 | |
| 1.5.0 | 0 / 6 | |
| 1.4.139 | 0 / 6 | |
| 1.4.137 | 0 / 6 | |
| 1.4.136 | 0 / 6 | |
| 1.4.134 | 0 / 6 | |
| 1.4.133 | 0 / 6 | |
| 1.4.132 | 0 / 6 | |
| 1.4.55 | 0 / 5 | |
| 1.4.54 | 0 / 5 | |
| 1.4.53 | 0 / 5 | |
| 1.4.52 | 0 / 5 | |
| 1.4.51 | 0 / 5 | |
| 1.4.50 | 0 / 5 | |
| 1.4.49 | 0 / 5 | |
| 1.4.48 | 0 / 5 | |
| 1.4.47 | 0 / 5 | |
| 1.4.46 | 0 / 5 | |
| 1.4.45 | 0 / 5 | |
| 1.4.44 | 0 / 5 | |
| 1.4.43 | 0 / 5 | |
| 1.4.42 | 0 / 5 | |
| 1.4.41 | 0 / 5 | |
| 1.4.40 | 0 / 5 | |
| 1.4.39 | 0 / 5 | |
| 1.4.38 | 0 / 5 | |
| 1.4.37 | 0 / 5 | |
| 1.4.36 | 0 / 5 |
v1.7.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (timur_rhinestone) than the most recent previously approved version (kopy-kat) on 2026-07-09, but timur_rhinestone is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.