← Home

@sonamu-kit/tasks

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

minsangkim

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:base64-decode AI (semgrep): Standard cursor pagination decode pattern; not obfuscation or payload hiding. ai
phantom-deps phantom-dep:pg AI (phantom-deps): TypeScript library with compiled output; imports may not be directly visible to static analyzer. ai
phantom-deps phantom-dep:zod AI (phantom-deps): TypeScript library with compiled output; imports may not be directly visible to static analyzer. ai
phantom-deps phantom-dep:rou3 AI (phantom-deps): TypeScript library with compiled output; imports may not be directly visible to static analyzer. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): TypeScript library with compiled output; imports may not be directly visible to static analyzer. ai
phantom-deps phantom-dep:date-fns AI (phantom-deps): TypeScript library with compiled output; imports may not be directly visible to static analyzer. ai
phantom-deps phantom-dep:node-cron AI (phantom-deps): TypeScript library with compiled output; imports may not be directly visible to static analyzer. ai
phantom-deps phantom-dep:date-fns-tz AI (phantom-deps): TypeScript library with compiled output; imports may not be directly visible to static analyzer. ai

Versions (showing 8 of 8)

Version Deps Published
0.3.0 10 / 7
0.2.0 10 / 9
0.1.3 10 / 9
0.1.2 10 / 9
0.1.1 10 / 8
0.1.0 10 / 8
0.0.2 10 / 8
0.0.1 9 / 9

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.