@rocicorp/zero
Zero is a web framework for serverless web development.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from manual publish to GitHub Actions CI/CD is a provenance improvement for this package. | ai | |
| provenance | missing-githead | AI (provenance): Established package with long history; publish environment change is plausible, not indicative of malicious activity. | ai | |
| provenance | no-provenance | AI (provenance): Well-established package; lack of Sigstore provenance is a process gap, not a security risk for this publisher. | ai | |
| phantom-deps | phantom-dep:@types/basic-auth | AI (phantom-deps): Type-only package; not directly imported at runtime by design. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-trace-node | AI (phantom-deps): Loaded via OpenTelemetry auto-instrumentation config; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:@fastify/cors | AI (phantom-deps): Loaded by convention via fastify plugin registration; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): semver is a declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): Type-only package; not directly imported at runtime by design. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env spread passes process.env to litestream subprocess — standard subprocess env forwarding, not exfiltration. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get inside a Proxy handler — idiomatic JS proxy pattern, not obfuscation. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function used in analyze-query CLI tool to evaluate user-supplied ZQL query strings — expected and documented behavior. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 1.8.0 | 49 / 20 | |
| 1.7.0 | 49 / 20 | |
| 1.6.2 | 49 / 20 | |
| 1.6.1 | 49 / 20 | |
| 1.6.0 | 49 / 20 | |
| 1.5.0 | 49 / 21 | |
| 1.4.0 | 49 / 21 | |
| 1.3.0 | 49 / 21 | |
| 1.2.0 | 50 / 21 | |
| 1.1.1 | 50 / 21 | |
| 1.1.0 | 50 / 21 | |
| 1.0.0 | 50 / 20 | |
| 0.26.2 | 50 / 20 | |
| 0.26.1 | 50 / 19 | |
| 0.26.0 | 49 / 19 | |
| 0.25.13 | 49 / 20 | |
| 0.25.12 | 49 / 20 | |
| 0.25.11 | 49 / 20 | |
| 0.25.10 | 49 / 20 | |
| 0.25.9 | 49 / 20 | |
| 0.25.8 | 49 / 20 | |
| 0.25.7 | 49 / 20 | |
| 0.25.6 | 49 / 20 | |
| 0.25.5 | 49 / 20 | |
| 0.25.4 | 49 / 20 | |
| 0.25.3 | 49 / 20 | |
| 0.25.2 | 49 / 20 | |
| 0.25.1 | 49 / 20 | |
| 0.25.0 | 48 / 20 | |
| 0.24.3000000000 | 48 / 20 | |
| 0.23.3000000000 | 49 / 17 | |
| 0.22.3000000000 | 50 / 15 |
v1.8.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v1.7.0
3 findingsThis version was published by a different npm account than previous versions on 2026-06-29. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v1.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.9
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aboodman) than the most recent previously approved version (0xcadams) on 2026-01-13, but aboodman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.25.8
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aboodman) than the most recent previously approved version (0xcadams) on 2026-01-09, but aboodman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.25.7
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (0xcadams) than the most recent previously approved version (aboodman) on 2026-01-05, but 0xcadams is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.25.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.3000000000
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.3000000000
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.3000000000
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.