@smartsoft001/nestjs
 
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit dependency in NestJS ecosystem; stable pattern. | ai | |
| dependencies | unvetted-dep:@nestjs/testing | AI (dependencies): @nestjs/testing is a well-known official NestJS package; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 722 versions; lack of provenance is consistent across its history and not a new risk signal. | ai | |
| phantom-deps | phantom-dep:@nestjs/testing | AI (phantom-deps): @nestjs/testing is declared as a dependency and referenced in config; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 61 of 61)
| Version | Deps | Published |
|---|---|---|
| 2.124.0 | 7 / 0 | |
| 2.123.0 | 7 / 0 | |
| 2.122.0 | 7 / 0 | |
| 2.121.0 | 7 / 0 | |
| 2.120.0 | 7 / 0 | |
| 2.119.0 | 7 / 0 | |
| 2.118.0 | 7 / 0 | |
| 2.117.0 | 7 / 0 | |
| 2.116.0 | 7 / 0 | |
| 2.115.0 | 7 / 0 | |
| 2.114.0 | 7 / 0 | |
| 2.113.0 | 7 / 0 | |
| 2.112.0 | 7 / 0 | |
| 2.111.0 | 7 / 0 | |
| 2.110.0 | 7 / 0 | |
| 2.109.0 | 7 / 0 | |
| 2.108.0 | 7 / 0 | |
| 2.107.0 | 7 / 0 | |
| 2.106.0 | 7 / 0 | |
| 2.105.0 | 7 / 0 | |
| 2.104.0 | 7 / 0 | |
| 2.103.0 | 7 / 0 | |
| 2.102.0 | 7 / 0 | |
| 2.101.0 | 7 / 0 | |
| 2.100.0 | 7 / 0 | |
| 2.99.0 | 7 / 0 | |
| 2.98.0 | 7 / 0 | |
| 2.97.0 | 7 / 0 | |
| 2.96.0 | 7 / 0 | |
| 2.95.0 | 7 / 0 | |
| 2.94.0 | 7 / 0 | |
| 2.93.0 | 7 / 0 | |
| 2.92.0 | 7 / 0 | |
| 2.91.0 | 7 / 0 | |
| 2.90.0 | 7 / 0 | |
| 2.89.0 | 7 / 0 | |
| 2.88.0 | 7 / 0 | |
| 2.87.0 | 7 / 0 | |
| 2.86.0 | 7 / 0 | |
| 2.85.0 | 7 / 0 | |
| 2.84.0 | 7 / 0 | |
| 2.83.0 | 7 / 0 | |
| 2.82.0 | 7 / 0 | |
| 2.81.0 | 7 / 0 | |
| 2.80.0 | 7 / 0 | |
| 2.76.0 | 7 / 0 | |
| 2.75.0 | 7 / 0 | |
| 2.74.0 | 7 / 0 | |
| 2.73.0 | 7 / 0 | |
| 2.72.0 | 7 / 0 | |
| 2.71.0 | 7 / 0 | |
| 2.70.0 | 7 / 0 | |
| 2.69.0 | 7 / 0 | |
| 2.68.0 | 7 / 0 | |
| 2.67.0 | 7 / 0 | |
| 2.66.0 | 7 / 0 | |
| 2.65.0 | 7 / 0 | |
| 2.64.0 | 7 / 0 | |
| 2.62.0 | 7 / 0 | |
| 2.61.0 | 7 / 0 | |
| 2.60.0 | 7 / 0 |
v2.64.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.62.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.61.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.60.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.