← Home

@rocicorp/zero

Zero is a web framework for serverless web development.

32
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

arvaboodmancesaraz1grgbkr0xcadamstantamandarick

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD is a provenance improvement for this package. ai
provenance missing-githead AI (provenance): Established package with long history; publish environment change is plausible, not indicative of malicious activity. ai
provenance no-provenance AI (provenance): Well-established package; lack of Sigstore provenance is a process gap, not a security risk for this publisher. ai
phantom-deps phantom-dep:@types/basic-auth AI (phantom-deps): Type-only package; not directly imported at runtime by design. ai
phantom-deps phantom-dep:@opentelemetry/sdk-trace-node AI (phantom-deps): Loaded via OpenTelemetry auto-instrumentation config; phantom-dep false positive. ai
phantom-deps phantom-dep:@fastify/cors AI (phantom-deps): Loaded by convention via fastify plugin registration; phantom-dep false positive. ai
phantom-deps phantom-dep:semver AI (phantom-deps): semver is a declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@types/ws AI (phantom-deps): Type-only package; not directly imported at runtime by design. ai
semgrep semgrep:env-spread AI (semgrep): env spread passes process.env to litestream subprocess — standard subprocess env forwarding, not exfiltration. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get inside a Proxy handler — idiomatic JS proxy pattern, not obfuscation. ai
semgrep semgrep:new-function-constructor AI (semgrep): new Function used in analyze-query CLI tool to evaluate user-supplied ZQL query strings — expected and documented behavior. ai

Versions (showing 32 of 32)

Version Deps Published
1.8.0 49 / 20
1.7.0 49 / 20
1.6.2 49 / 20
1.6.1 49 / 20
1.6.0 49 / 20
1.5.0 49 / 21
1.4.0 49 / 21
1.3.0 49 / 21
1.2.0 50 / 21
1.1.1 50 / 21
1.1.0 50 / 21
1.0.0 50 / 20
0.26.2 50 / 20
0.26.1 50 / 19
0.26.0 49 / 19
0.25.13 49 / 20
0.25.12 49 / 20
0.25.11 49 / 20
0.25.10 49 / 20
0.25.9 49 / 20
0.25.8 49 / 20
0.25.7 49 / 20
0.25.6 49 / 20
0.25.5 49 / 20
0.25.4 49 / 20
0.25.3 49 / 20
0.25.2 49 / 20
0.25.1 49 / 20
0.25.0 48 / 20
0.24.3000000000 48 / 20
0.23.3000000000 49 / 17
0.22.3000000000 50 / 15

v1.8.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v1.7.0

3 findings
HIGH Publisher changed: arv → GitHub Actions (on 2026-06-29) provenance

This version was published by a different npm account than previous versions on 2026-06-29. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v1.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.9

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: 0xcadams → aboodman (on 2026-01-13, known maintainer) provenance

This version was published by a different npm account (aboodman) than the most recent previously approved version (0xcadams) on 2026-01-13, but aboodman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.25.8

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: 0xcadams → aboodman (on 2026-01-09, known maintainer) provenance

This version was published by a different npm account (aboodman) than the most recent previously approved version (0xcadams) on 2026-01-09, but aboodman is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.25.7

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: aboodman → 0xcadams (on 2026-01-05, known maintainer) provenance

This version was published by a different npm account (0xcadams) than the most recent previously approved version (aboodman) on 2026-01-05, but 0xcadams is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.25.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.3000000000

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.23.3000000000

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.3000000000

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.