← Home

@semiont/content

Content-addressed storage for resource representations

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

adamaialliance

Keywords

contentstorageworking-treechecksumpdfsemiont

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@vitest/ui AI (phantom-deps): @vitest/ui is a test tooling package mistakenly in runtime deps; not imported at runtime, stable false positive. ai
provenance slsa-provenance AI (provenance): SLSA provenance via Sigstore CI/CD; stable positive signal for this package. ai

Versions (showing 51 of 71)

View all versions
Version Deps Published
0.5.21 2 / 7
0.5.20 2 / 7
0.5.19 2 / 7
0.5.18 2 / 7
0.5.17 2 / 7
0.5.16 2 / 7
0.5.15 2 / 7
0.5.14 2 / 7
0.5.13 2 / 7
0.5.12 2 / 7
0.5.11 2 / 7
0.5.10 2 / 7
0.5.9 2 / 7
0.5.8 2 / 7
0.5.7 2 / 7
0.5.6 2 / 7
0.5.5 1 / 5
0.5.4 1 / 3
0.5.3 1 / 3
0.5.2 1 / 3
0.5.1 1 / 3
0.5.0 1 / 3
0.4.22 1 / 3
0.4.21 1 / 3
0.4.20 1 / 3
0.4.19 1 / 3
0.4.18 1 / 3
0.4.17 1 / 3
0.4.16 1 / 3
0.4.15 1 / 3
0.4.14 1 / 3
0.4.13 1 / 3
0.4.12 1 / 3
0.4.11 1 / 3
0.4.10 1 / 3
0.4.9 1 / 3
0.4.7 1 / 3
0.4.6 1 / 3
0.4.5 1 / 3
0.4.4 1 / 3
0.4.3 1 / 3
0.4.2 2 / 4
0.4.1 2 / 4
0.4.0 2 / 4
0.3.8 2 / 4
0.3.7 2 / 4
0.3.6 2 / 4
0.3.5 2 / 4
0.3.4 1 / 4
0.3.3 1 / 4
0.3.2 1 / 4

v0.5.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.