@socialgouv/cdtn-elasticsearch
SocialGouv - Code du travail numerique - Infrastructure - Elasticsearch
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from socialgroovybot to GitHub Actions CI publishing is a legitimate automation change, backed by SLSA attestation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by CI/CD-automated publish with SLSA provenance; consistent with org-level tooling migration. | ai |
Versions (showing 51 of 100)
| Version | Deps | Published |
|---|---|---|
| 2.77.9 | 0 / 6 | |
| 2.77.8 | 0 / 6 | |
| 2.77.7 | 0 / 6 | |
| 2.77.6 | 0 / 6 | |
| 2.77.5 | 0 / 6 | |
| 2.77.4 | 0 / 6 | |
| 2.77.3 | 0 / 6 | |
| 2.77.2 | 0 / 6 | |
| 2.77.1 | 0 / 6 | |
| 2.74.0 | 0 / 6 | |
| 2.73.4 | 0 / 6 | |
| 2.73.3 | 0 / 6 | |
| 2.73.2 | 0 / 6 | |
| 2.73.1 | 0 / 6 | |
| 2.73.0 | 0 / 6 | |
| 2.72.3 | 0 / 6 | |
| 2.72.2 | 0 / 6 | |
| 2.72.1 | 0 / 6 | |
| 2.71.0 | 0 / 6 | |
| 2.70.1 | 0 / 6 | |
| 2.70.0 | 0 / 6 | |
| 2.69.0 | 0 / 6 | |
| 2.68.1 | 0 / 5 | |
| 2.68.0 | 0 / 5 | |
| 2.67.3 | 0 / 5 | |
| 2.67.2 | 0 / 5 | |
| 2.67.1 | 0 / 5 | |
| 2.67.0 | 0 / 5 | |
| 2.66.6 | 0 / 5 | |
| 2.66.5 | 0 / 5 | |
| 2.66.4 | 0 / 5 | |
| 2.66.3 | 0 / 5 | |
| 2.66.2 | 0 / 5 | |
| 2.66.1 | 0 / 5 | |
| 2.66.0 | 0 / 5 | |
| 2.65.3 | 0 / 5 | |
| 2.65.2 | 0 / 5 | |
| 2.65.1 | 0 / 5 | |
| 2.65.0 | 0 / 5 | |
| 2.64.0 | 0 / 5 | |
| 2.63.0 | 0 / 5 | |
| 2.62.8 | 0 / 5 | |
| 2.62.0 | 0 / 5 | |
| 2.61.0 | 0 / 5 | |
| 2.60.0 | 0 / 5 | |
| 2.59.0 | 0 / 5 | |
| 2.58.5 | 0 / 5 | |
| 2.58.4 | 0 / 5 | |
| 2.58.3 | 0 / 5 | |
| 2.58.2 | 0 / 5 | |
| 2.58.1 | 0 / 5 |
v2.77.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.