@stacksjs/ts-cloud
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Frequent CI-driven releases are normal for this actively maintained package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are bundled dashboard HTML assets, matching serverless UI feature. | ai | |
| dependencies | unvetted-dep:@stacksjs/ts-xml | AI (dependencies): Same org scope (@stacksjs); already accepted as phantom-dep; low risk in context. | ai | |
| phantom-deps | phantom-dep:@stacksjs/ts-xml | AI (phantom-deps): Same-org dependency declared in package.json; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 0.7.60 | 3 / 2 | |
| 0.7.59 | 3 / 2 | |
| 0.7.58 | 3 / 2 | |
| 0.7.56 | 3 / 2 | |
| 0.7.53 | 3 / 2 | |
| 0.7.51 | 3 / 2 | |
| 0.7.43 | 3 / 2 | |
| 0.7.39 | 3 / 2 | |
| 0.7.23 | 3 / 2 | |
| 0.5.22 | 3 / 2 | |
| 0.5.11 | 3 / 2 | |
| 0.2.16 | 3 / 2 | |
| 0.2.15 | 3 / 2 | |
| 0.2.5 | 3 / 2 | |
| 0.2.1 | 3 / 2 | |
| 0.2.0 | 3 / 2 | |
| 0.1.8 | 4 / 2 |
v0.7.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.58
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.