@socialgouv/cdtn-elasticsearch
SocialGouv - Code du travail numerique - Infrastructure - Elasticsearch
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from socialgroovybot to GitHub Actions CI publishing is a legitimate automation change, backed by SLSA attestation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by CI/CD-automated publish with SLSA provenance; consistent with org-level tooling migration. | ai |
Versions (showing 100 of 100)
| Version | Deps | Published |
|---|---|---|
| 2.77.9 | 0 / 6 | |
| 2.77.8 | 0 / 6 | |
| 2.77.7 | 0 / 6 | |
| 2.77.6 | 0 / 6 | |
| 2.77.5 | 0 / 6 | |
| 2.77.4 | 0 / 6 | |
| 2.77.3 | 0 / 6 | |
| 2.77.2 | 0 / 6 | |
| 2.77.1 | 0 / 6 | |
| 2.74.0 | 0 / 6 | |
| 2.73.4 | 0 / 6 | |
| 2.73.3 | 0 / 6 | |
| 2.73.2 | 0 / 6 | |
| 2.73.1 | 0 / 6 | |
| 2.73.0 | 0 / 6 | |
| 2.72.3 | 0 / 6 | |
| 2.72.2 | 0 / 6 | |
| 2.72.1 | 0 / 6 | |
| 2.71.0 | 0 / 6 | |
| 2.70.1 | 0 / 6 | |
| 2.70.0 | 0 / 6 | |
| 2.69.0 | 0 / 6 | |
| 2.68.1 | 0 / 5 | |
| 2.68.0 | 0 / 5 | |
| 2.67.3 | 0 / 5 | |
| 2.67.2 | 0 / 5 | |
| 2.67.1 | 0 / 5 | |
| 2.67.0 | 0 / 5 | |
| 2.66.6 | 0 / 5 | |
| 2.66.5 | 0 / 5 | |
| 2.66.4 | 0 / 5 | |
| 2.66.3 | 0 / 5 | |
| 2.66.2 | 0 / 5 | |
| 2.66.1 | 0 / 5 | |
| 2.66.0 | 0 / 5 | |
| 2.65.3 | 0 / 5 | |
| 2.65.2 | 0 / 5 | |
| 2.65.1 | 0 / 5 | |
| 2.65.0 | 0 / 5 | |
| 2.64.0 | 0 / 5 | |
| 2.63.0 | 0 / 5 | |
| 2.62.8 | 0 / 5 | |
| 2.62.0 | 0 / 5 | |
| 2.61.0 | 0 / 5 | |
| 2.60.0 | 0 / 5 | |
| 2.59.0 | 0 / 5 | |
| 2.58.5 | 0 / 5 | |
| 2.58.4 | 0 / 5 | |
| 2.58.3 | 0 / 5 | |
| 2.58.2 | 0 / 5 | |
| 2.58.1 | 0 / 5 | |
| 2.58.0 | 0 / 5 | |
| 2.57.6 | 0 / 5 | |
| 2.57.5 | 0 / 5 | |
| 2.57.4 | 0 / 5 | |
| 2.57.3 | 0 / 5 | |
| 2.57.2 | 0 / 5 | |
| 2.57.1 | 0 / 5 | |
| 2.57.0 | 0 / 5 | |
| 2.56.2 | 0 / 5 | |
| 2.56.1 | 0 / 5 | |
| 2.56.0 | 0 / 5 | |
| 2.55.1 | 0 / 5 | |
| 2.55.0 | 0 / 5 | |
| 2.54.3 | 0 / 5 | |
| 2.54.2 | 0 / 5 | |
| 2.54.1 | 0 / 5 | |
| 2.54.0 | 0 / 5 | |
| 2.53.0 | 0 / 5 | |
| 2.52.3 | 0 / 5 | |
| 2.52.2 | 0 / 5 | |
| 2.52.1 | 0 / 5 | |
| 2.52.0 | 0 / 5 | |
| 2.51.0 | 0 / 5 | |
| 2.50.4 | 0 / 5 | |
| 2.50.3 | 0 / 5 | |
| 2.50.2 | 0 / 5 | |
| 2.50.1 | 0 / 5 | |
| 2.50.0 | 0 / 5 | |
| 2.49.4 | 0 / 5 | |
| 2.49.3 | 0 / 5 | |
| 2.49.2 | 0 / 5 | |
| 2.49.1 | 0 / 5 | |
| 2.49.0 | 0 / 5 | |
| 2.48.1 | 0 / 5 | |
| 2.48.0 | 0 / 5 | |
| 2.47.2 | 0 / 5 | |
| 2.47.1 | 0 / 5 | |
| 2.47.0 | 0 / 5 | |
| 2.46.7 | 0 / 5 | |
| 2.46.6 | 0 / 5 | |
| 2.46.5 | 0 / 5 | |
| 2.46.4 | 0 / 5 | |
| 2.46.3 | 0 / 5 | |
| 2.46.2 | 0 / 5 | |
| 2.46.1 | 0 / 5 | |
| 2.46.0 | 0 / 5 | |
| 2.45.0 | 1 / 5 | |
| 2.44.2 | 1 / 5 | |
| 2.44.1 | 1 / 5 |
v2.77.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.57.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.56.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.56.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.56.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.55.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.55.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.54.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.54.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.54.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.54.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.53.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.52.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.52.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.52.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.52.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.51.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.50.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.50.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.50.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.50.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.50.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.49.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.49.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.49.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.49.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.49.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.48.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.48.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.47.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.47.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.47.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.44.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.44.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.