@strapi/provider-upload-local
Local provider for strapi upload
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Package is part of Strapi monorepo with coordinated releases; dormancy metric reflects this sub-package's publish cadence, not actual project inactivity. | ai | |
| license | uncommon-license:SEE LICENSE IN LICENSE | AI (license): Standard Strapi license declaration used across all @strapi/* packages; not a security concern and stable for this package namespace. | ai | |
| provenance | no-provenance | AI (provenance): Established Strapi monorepo package with 183k weekly downloads and 2276 versions; lack of Sigstore provenance is consistent across all prior releases. | ai |
Versions (showing 51 of 96)
| Version | Deps | Published |
|---|---|---|
| 5.51.0 | 2 / 8 | |
| 5.50.2 | 2 / 8 | |
| 5.50.1 | 2 / 6 | |
| 5.50.0 | 2 / 6 | |
| 5.49.0 | 2 / 6 | |
| 5.48.1 | 2 / 6 | |
| 5.48.0 | 2 / 6 | |
| 5.47.1 | 2 / 6 | |
| 5.47.0 | 2 / 6 | |
| 5.46.1 | 2 / 6 | |
| 5.46.0 | 2 / 6 | |
| 5.45.1 | 2 / 6 | |
| 5.45.0 | 2 / 6 | |
| 5.44.0 | 2 / 6 | |
| 5.43.0 | 2 / 6 | |
| 5.42.1 | 2 / 6 | |
| 5.42.0 | 2 / 6 | |
| 5.41.1 | 2 / 6 | |
| 5.41.0 | 2 / 6 | |
| 5.32.0 | 2 / 6 | |
| 5.31.3 | 2 / 6 | |
| 5.31.2 | 2 / 6 | |
| 5.31.1 | 2 / 6 | |
| 5.31.0 | 2 / 6 | |
| 5.30.1 | 2 / 6 | |
| 5.30.0 | 2 / 6 | |
| 5.29.0 | 2 / 6 | |
| 5.28.0 | 2 / 6 | |
| 5.27.0 | 2 / 6 | |
| 5.26.0 | 2 / 6 | |
| 5.25.0 | 2 / 6 | |
| 5.24.2 | 2 / 6 | |
| 5.24.1 | 2 / 6 | |
| 5.24.0 | 2 / 6 | |
| 5.23.6 | 2 / 6 | |
| 5.23.5 | 2 / 6 | |
| 5.23.4 | 2 / 6 | |
| 5.23.3 | 2 / 6 | |
| 5.23.2 | 2 / 6 | |
| 5.23.1 | 2 / 6 | |
| 5.23.0 | 2 / 6 | |
| 5.22.0 | 2 / 6 | |
| 5.21.0 | 2 / 6 | |
| 5.20.0 | 2 / 6 | |
| 5.19.0 | 2 / 6 | |
| 5.18.1 | 2 / 6 | |
| 5.18.0 | 2 / 6 | |
| 5.17.0 | 2 / 6 | |
| 5.16.1 | 2 / 6 | |
| 5.16.0 | 2 / 6 | |
| 5.15.1 | 2 / 6 |
v5.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.