@scalar/api-reference
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-YU9KKgvZ.js | AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-WJ4Gcv8N.js | AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-B-Nhpn0q.js | AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BqFs9NIb.js | AI (source-diff): Bundled vendor chunk; net+exec patterns are library code, no hostile target. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-7kt1IXrE.js | AI (source-diff): Vendor bundle for a browser API-reference component; net/exec are library primitives, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BkjPSVNK.js | AI (source-diff): Vite/Rollup minified browser bundle with Scalar banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-CI1RYR0j.js | AI (source-diff): Minified bundled browser chunk; benign build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-CnSl7YW1.js | AI (source-diff): Minified bundled Vue component chunk; benign build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-BLBi4S4R.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-D7J_MHKY.js | AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-DHN5fsxL.js | AI (source-diff): Bundled vendor chunk; net+exec is browser-runtime library code, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Fb0snAee.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BPQqqkn-.js | AI (source-diff): Bundled vendor chunk; net+exec are library primitives, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-CysYmeeN.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-wI0tG53V.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-C3QiXv0S.js | AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-B4LeCbAi.js | AI (source-diff): Minified Vite bundle; normal ESM imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-D4DCmV5y.js | AI (source-diff): Minified Vite bundle with Scalar banner; long lines are build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BNhbieDE.js | AI (source-diff): Vendor browser bundle; net+exec patterns inherent to bundled deps, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-C5aaO8tA.js | AI (source-diff): Minified Vue component bundle; build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-Dp5Q6nDX.js | AI (source-diff): Bundled vendor chunk of a browser API-reference UI; network+eval is normal Vue runtime, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CPqxdcxM.js | AI (source-diff): Minified vite bundle output, not obfuscation; per-file path won't recur but pattern is benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/src-DJwsRvMU.js | AI (source-diff): Bundled Vite build output, readable ESM imports; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-DfHAfVG5.js | AI (source-diff): Bundled minified Vue component chunk. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-uEJhFXkB.js | AI (source-diff): Bundled minified dist chunk, build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-VSnkfbyL.js | AI (source-diff): Bundled minified dist chunk with Scalar banner, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-C5HmjoOQ.js | AI (source-diff): Minified Vite vendor bundle; long lines are build output, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BhUn0w1j.js | AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BeJNu9KM.js | AI (source-diff): Bundled vendor chunk; net+exec patterns are inherent to browser bundle, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-BUzf4Z_k.js | AI (source-diff): Vite-bundled dist chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-CZI71Aau.js | AI (source-diff): Vite-bundled dist chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-B2flFlrc.js | AI (source-diff): Bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DX-rWLia.js | AI (source-diff): Vite-bundled dist chunk, long lines are minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-DuE2oAzR.js | AI (source-diff): Bundled dist chunk; minified build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-DPVN2O_H.js | AI (source-diff): Bundled vendor chunk; net+exec patterns are Vue runtime build output, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Cg0WEkPQ.js | AI (source-diff): Minified Vite bundle chunk; build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-DfF1NNVy.js | AI (source-diff): Bundled Vue vendor chunk; net+exec is standard browser runtime, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-Bd03__M5.js | AI (source-diff): Minified Vite bundle chunk with Scalar banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-DXAlZ4Y8.js | AI (source-diff): Minified Vite bundle chunk; build output. | ai | |
| source-diff | obfuscated-file:dist/src-DqcYVBWI.js | AI (source-diff): Vite/rollup bundle output with readable ESM imports, not obfuscation; stable for this build tool. | ai | |
| source-diff | obfuscated-file:dist/components/GettingStarted.vue.script.js | AI (source-diff): Vite/Vue bundled component output, not obfuscation; readable imports and first-party fetch target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-c6CQmaLr.js | AI (source-diff): Vite-bundled minified chunk with Scalar banner, not obfuscation. | ai | |
| dependencies | unvetted-dep:@scalar/client-app | AI (dependencies): First-party sibling package in the same monorepo. | ai | |
| phantom-deps | phantom-dep:unhead | AI (phantom-deps): Used in config, not a real risk. | ai | |
| phantom-deps | phantom-dep:unified | AI (phantom-deps): Used via config files, not direct import; benign. | ai | |
| phantom-deps | phantom-dep:postcss-nested | AI (phantom-deps): Used via PostCSS config, not direct import; stable false positive. | ai | |
| dependencies | unvetted-dep:@scalar/api-client-modal | AI (dependencies): First-party @scalar sibling package within same monorepo. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-BvqLUPs5.js | AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BlFFskFr.js | AI (source-diff): Bundled vendor chunk; net+exec are inherent to browser bundle, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CNs5mxby.js | AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-D_L-rtQC.js | AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-DQLVQL1H.js | AI (source-diff): Minified bundle chunk, official banner; build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-CMNc6l_z.js | AI (source-diff): Standard vendor bundle for browser build; dual-use in minified output, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Cb7P6-e4.js | AI (source-diff): Minified Vue component bundle chunk; build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DeQ6jlD2.js | AI (source-diff): Vite/Rollup minified bundle chunk with official Scalar banner; build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-wW8jg8wN.js | AI (source-diff): Vendor bundle from Vite build; network+exec patterns are from bundled dependencies (Vue, etc.). | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-BZzcBkVp.js | AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CesFQ_Ax.js | AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-C14zmVNI.js | AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:flatted | AI (phantom-deps): Declared dep used transitively or in config; stable pattern for this package. | ai | |
| provenance | publisher-changed | AI (provenance): scalar_geoff is an established Scalar org publisher with 446 approved packages. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-Dv0uBVU9.js | AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-Cx_C-51y.js | AI (source-diff): Vendor bundle from Vite build; network+exec patterns are from bundled dependencies. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-ZmlutrTU.js | AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-DHI6k89v.js | AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. | ai | |
| source-diff | encoded-string-file:dist/browser/standalone.js | AI (source-diff): Bundled standalone build with CodeMirror bidi char-class tables; stable minified output pattern. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-nugWm4eq.js | AI (source-diff): Bundled vendor chunk for browser dist; network+exec pattern is normal for UI framework bundles. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-XkIzhvc0.js | AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-Bp9V4D2s.js | AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BXB1nZKJ.js | AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@scalar/openapi-upgrader | AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. | ai | |
| phantom-deps | phantom-dep:@scalar/object-utils | AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. | ai | |
| phantom-deps | phantom-dep:@scalar/json-magic | AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. | ai | |
| phantom-deps | phantom-dep:@floating-ui/vue | AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:type-fest | AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:js-base64 | AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/browser-67K6wmG9.js | AI (source-diff): Vite-bundled browser standalone chunk with standard minification; stable pattern for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New standalone ESM build target adds expected browser bundle chunks. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DIIVMX31.js | AI (source-diff): Vite-bundled browser standalone chunk with standard minification; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@scalar/themes | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/workspace-store | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/use-toasts | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/components | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/api-client | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/agent-chat | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/use-hooks | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/oas-utils | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/sidebar | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/icons | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai |
Versions (showing 95 of 395)
| Version | Deps | Published |
|---|---|---|
| 1.25.25 | 24 / 23 | |
| 1.25.24 | 24 / 23 | |
| 1.25.23 | 24 / 23 | |
| 1.25.22 | 24 / 23 | |
| 1.25.21 | 24 / 23 | |
| 1.25.20 | 24 / 23 | |
| 1.25.19 | 24 / 23 | |
| 1.25.18 | 24 / 23 | |
| 1.25.17 | 24 / 23 | |
| 1.25.16 | 24 / 23 | |
| 1.25.14 | 24 / 23 | |
| 1.25.13 | 24 / 23 | |
| 1.25.12 | 24 / 23 | |
| 1.25.11 | 24 / 23 | |
| 1.25.10 | 24 / 23 | |
| 1.25.9 | 24 / 23 | |
| 1.25.7 | 24 / 23 | |
| 1.25.6 | 24 / 23 | |
| 1.25.5 | 24 / 23 | |
| 1.25.4 | 24 / 23 | |
| 1.25.3 | 24 / 23 | |
| 1.25.2 | 24 / 23 | |
| 1.25.1 | 24 / 23 | |
| 1.25.0 | 24 / 23 | |
| 1.24.77 | 23 / 23 | |
| 1.24.76 | 23 / 23 | |
| 1.24.75 | 23 / 23 | |
| 1.24.74 | 23 / 23 | |
| 1.24.73 | 23 / 23 | |
| 1.24.72 | 23 / 23 | |
| 1.24.71 | 22 / 23 | |
| 1.24.70 | 22 / 23 | |
| 1.24.69 | 22 / 23 | |
| 1.24.68 | 22 / 23 | |
| 1.24.67 | 22 / 23 | |
| 1.24.66 | 22 / 23 | |
| 1.24.65 | 22 / 23 | |
| 1.24.64 | 22 / 23 | |
| 1.24.63 | 22 / 23 | |
| 1.24.62 | 22 / 23 | |
| 1.24.61 | 22 / 23 | |
| 1.24.60 | 22 / 23 | |
| 1.24.59 | 22 / 23 | |
| 1.24.58 | 22 / 23 | |
| 1.24.57 | 22 / 23 | |
| 1.24.56 | 22 / 23 | |
| 1.24.55 | 22 / 23 | |
| 1.24.54 | 22 / 23 | |
| 1.24.53 | 22 / 23 | |
| 1.24.52 | 22 / 26 | |
| 1.24.51 | 22 / 26 | |
| 1.24.50 | 22 / 26 | |
| 1.24.49 | 22 / 26 | |
| 1.24.48 | 22 / 26 | |
| 1.24.46 | 22 / 26 | |
| 1.24.45 | 22 / 26 | |
| 1.24.44 | 22 / 26 | |
| 1.24.43 | 22 / 26 | |
| 1.24.42 | 22 / 26 | |
| 1.24.41 | 22 / 26 | |
| 1.24.40 | 22 / 26 | |
| 1.24.39 | 22 / 26 | |
| 1.24.38 | 22 / 26 | |
| 1.24.37 | 22 / 26 | |
| 1.24.36 | 22 / 26 | |
| 1.24.35 | 22 / 26 | |
| 1.24.34 | 22 / 26 | |
| 1.24.33 | 22 / 26 | |
| 1.24.31 | 22 / 26 | |
| 1.24.30 | 22 / 26 | |
| 1.24.29 | 22 / 26 | |
| 1.24.28 | 22 / 26 | |
| 1.24.27 | 22 / 26 | |
| 1.24.26 | 22 / 26 | |
| 1.24.25 | 22 / 26 | |
| 1.24.24 | 22 / 26 | |
| 1.24.23 | 22 / 26 | |
| 1.24.21 | 21 / 26 | |
| 1.24.20 | 21 / 26 | |
| 1.24.19 | 21 / 25 | |
| 1.24.17 | 21 / 25 | |
| 1.24.16 | 21 / 25 | |
| 1.24.15 | 21 / 25 | |
| 1.24.13 | 20 / 25 | |
| 1.24.12 | 20 / 25 | |
| 1.24.11 | 20 / 25 | |
| 1.24.10 | 20 / 25 | |
| 1.24.8 | 20 / 25 | |
| 1.24.7 | 20 / 25 | |
| 1.24.6 | 20 / 25 | |
| 1.24.5 | 18 / 26 | |
| 1.24.4 | 18 / 26 | |
| 1.24.3 | 18 / 26 | |
| 1.24.1 | 18 / 26 | |
| 1.24.0 | 18 / 26 |
v1.25.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.77
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.76
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.73
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.72
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.70
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.69
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.68
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.67
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.66
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.65
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.64
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.63
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.58
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.57
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.