← Home

@spinajs/http

framework HTTP module base on express.js

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

gben-spina

Keywords

spinajshttp

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:glob AI (phantom-deps): glob is a declared runtime dependency in package.json; phantom-dep heuristic is a false positive here. ai
provenance no-provenance AI (provenance): Established monorepo package; lack of provenance is consistent across all versions and not a risk indicator here. ai

Versions (showing 51 of 403)

View all versions
Version Deps Published
2.0.486 27 / 12
2.0.485 27 / 12
2.0.484 27 / 12
2.0.482 27 / 12
2.0.481 25 / 11
2.0.480 25 / 11
2.0.479 25 / 11
2.0.478 25 / 11
2.0.477 25 / 11
2.0.476 25 / 11
2.0.475 25 / 11
2.0.474 25 / 11
2.0.473 25 / 11
2.0.472 25 / 11
2.0.471 25 / 11
2.0.470 25 / 11
2.0.469 25 / 11
2.0.468 24 / 11
2.0.467 24 / 11
2.0.466 24 / 11
2.0.465 24 / 11
2.0.464 24 / 11
2.0.463 24 / 11
2.0.462 24 / 11
2.0.461 24 / 11
2.0.460 24 / 11
2.0.458 24 / 11
2.0.457 24 / 11
2.0.456 24 / 11
2.0.455 24 / 11
2.0.454 24 / 11
2.0.453 24 / 11
2.0.452 24 / 11
2.0.451 24 / 11
2.0.450 24 / 11
2.0.449 24 / 11
2.0.448 24 / 11
2.0.447 24 / 11
2.0.446 24 / 11
2.0.445 24 / 11
2.0.444 24 / 11
2.0.443 24 / 11
2.0.442 24 / 11
2.0.441 24 / 11
2.0.439 24 / 11
2.0.438 24 / 11
2.0.436 24 / 11
2.0.435 24 / 11
2.0.434 24 / 11
2.0.433 24 / 11
2.0.432 24 / 11

v2.0.486

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.485

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.484

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.482

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.