@sanity/util
Utilities shared across projects of Sanity
51
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
sanity-svc.npmsanity-io
Keywords
cmscontentheadlessrealtimesanityutil
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): sanity-svc.npm is Sanity's CI service account with strong track record; publisher change is org-level consolidation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Same rationale: sanity-svc.npm is the org's CI publisher, not a hostile takeover. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @sanity/util is a legitimate Sanity monorepo package; Levenshtein match to uuid is a false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package with minimal root index.js and sparse README is expected; not a spam/bogus package. | ai |
Versions (showing 51 of 61)
| Version | Deps | Published |
|---|---|---|
| 6.6.0 | 6 / 9 | |
| 6.5.0 | 6 / 9 | |
| 6.4.0 | 6 / 9 | |
| 6.3.0 | 6 / 9 | |
| 6.2.0 | 6 / 9 | |
| 6.1.0 | 6 / 11 | |
| 6.0.0 | 6 / 11 | |
| 5.31.1 | 6 / 11 | |
| 5.31.0 | 6 / 11 | |
| 5.30.0 | 6 / 10 | |
| 5.29.0 | 6 / 10 | |
| 5.28.0 | 6 / 10 | |
| 5.27.0 | 6 / 10 | |
| 5.26.0 | 6 / 10 | |
| 5.25.1 | 6 / 10 | |
| 5.25.0 | 6 / 10 | |
| 5.23.0 | 6 / 10 | |
| 5.22.0 | 6 / 10 | |
| 5.21.0 | 6 / 10 | |
| 5.20.0 | 6 / 10 | |
| 5.19.0 | 6 / 10 | |
| 5.18.0 | 6 / 10 | |
| 5.17.1 | 6 / 10 | |
| 5.17.0 | 6 / 10 | |
| 5.16.0 | 6 / 10 | |
| 5.15.0 | 6 / 10 | |
| 5.14.1 | 6 / 10 | |
| 5.14.0 | 6 / 10 | |
| 5.13.0 | 6 / 10 | |
| 5.12.0 | 6 / 10 | |
| 5.11.0 | 6 / 10 | |
| 5.10.0 | 6 / 10 | |
| 5.9.0 | 6 / 10 | |
| 5.8.1 | 6 / 10 | |
| 5.8.0 | 6 / 10 | |
| 5.7.0 | 6 / 10 | |
| 5.6.0 | 6 / 10 | |
| 5.5.0 | 6 / 10 | |
| 5.4.0 | 6 / 10 | |
| 5.3.1 | 6 / 10 | |
| 5.3.0 | 6 / 10 | |
| 5.2.0 | 6 / 10 | |
| 5.1.0 | 6 / 10 | |
| 5.0.1 | 6 / 10 | |
| 5.0.0 | 6 / 10 | |
| 4.22.0 | 6 / 10 | |
| 4.21.1 | 6 / 10 | |
| 4.21.0 | 6 / 10 | |
| 4.20.3 | 6 / 10 | |
| 4.20.2 | 6 / 10 | |
| 4.20.1 | 6 / 10 |
v6.6.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.5.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.4.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.