@rocicorp/lock
3
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
arvaboodmancesaraz1grgbkr0xcadamstantamandarick
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation; gitHead absence is a minor metadata gap, not a supply chain risk. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD pipeline with SLSA attestation explains rapid successive publish; not indicative of malicious activity. | ai | |
| provenance | publisher-changed | AI (provenance): Rocicorp migrated publishing to GitHub Actions CI with SLSA attestation; this is a documented org-level practice. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Stable utility package; long gap between v1 and v2 is consistent with low-churn maintenance, not takeover. | ai |