← Home

@supabase/functions-js

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

etienne_supamandarini

Keywords

functionssupabase

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is a metadata quirk, not a security concern for this package. ai

Versions (showing 100 of 101)

Version Deps Published
2.110.9 1 / 12
2.110.8 1 / 12
2.110.7 1 / 12
2.110.6 1 / 12
2.110.5 1 / 12
2.110.4 1 / 12
2.110.3 1 / 12
2.110.2 1 / 12
2.110.1 1 / 12
2.110.0 1 / 12
2.109.0 1 / 12
2.108.2 1 / 12
2.108.1 1 / 12
2.108.0 1 / 12
2.107.0 1 / 12
2.106.2 1 / 12
2.106.1 1 / 4
2.106.0 1 / 4
2.105.4 1 / 4
2.105.3 1 / 4
2.105.2 1 / 4
2.105.1 1 / 4
2.105.0 1 / 4
2.104.1 1 / 4
2.104.0 1 / 4
2.103.3 1 / 4
2.103.2 1 / 4
2.103.1 1 / 4
2.103.0 1 / 4
2.102.1 1 / 4
2.102.0 1 / 4
2.101.1 1 / 4
2.101.0 1 / 4
2.100.1 1 / 4
2.100.0 1 / 4
2.99.3 1 / 4
2.99.2 1 / 4
2.99.1 1 / 4
2.99.0 1 / 4
2.98.0 1 / 4
2.97.0 1 / 4
2.96.0 1 / 4
2.95.3 1 / 4
2.95.2 1 / 4
2.95.1 1 / 4
2.95.0 1 / 4
2.94.1 1 / 4
2.94.0 1 / 4
2.93.3 1 / 4
2.93.2 1 / 4
2.93.1 1 / 4
2.93.0 1 / 4
2.92.0 1 / 4
2.91.2 1 / 4
2.91.1 1 / 4
2.91.0 1 / 4
2.90.1 1 / 4
2.90.0 1 / 4
2.89.0 1 / 4
2.88.0 1 / 4
2.87.3 1 / 4
2.87.2 1 / 4
2.87.1 1 / 4
2.87.0 1 / 4
2.86.2 1 / 4
2.86.1 1 / 4
2.86.0 1 / 4
2.85.0 1 / 4
2.84.0 1 / 4
2.83.0 1 / 4
2.82.0 1 / 4
2.81.1 1 / 4
2.81.0 1 / 4
2.80.0 1 / 4
2.79.0 1 / 4
2.78.0 2 / 4
2.77.0 2 / 7
2.76.1 2 / 7
2.76.0 1 / 7
2.75.1 1 / 7
2.75.0 1 / 7
2.74.0 1 / 7
2.5.0 1 / 19
2.4.6 1 / 19
2.4.5 1 / 19
2.4.4 1 / 19
2.4.3 1 / 19
2.4.2 1 / 19
2.4.1 1 / 19
2.4.0 1 / 19
2.3.1 1 / 18
2.3.0 1 / 18
2.2.2 1 / 18
2.2.0 1 / 18
2.1.5 1 / 18
2.1.4 1 / 18
2.1.3 1 / 18
2.1.2 1 / 18
2.1.1 1 / 18
2.1.0 1 / 18
Showing 100 of 101 Next page →

v2.110.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.109.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.