← Home

@supabase/realtime-js

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

etienne_supamandarini

Keywords

realtimephoenixelixirjavascripttypescriptfirebasesupabase

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Monorepo migration dropped gitHead; SLSA attestation provides stronger integrity signal. ai
semgrep semgrep:dynamic-require AI (semgrep): Controlled WebSocket module loader pattern; moduleId is not user-supplied, stable across versions. ai
phantom-deps phantom-dep:ws AI (phantom-deps): ws is a runtime peer dep used via dynamic require in the WebSocket factory; not a phantom dep concern. ai
phantom-deps phantom-dep:@types/phoenix AI (phantom-deps): Type-only package loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:@types/ws AI (phantom-deps): @types/ws is intentionally listed as a runtime dep to ship TypeScript types alongside the ws package; this is a packaging style choice, not a security issue. ai

Versions (showing 51 of 144)

View all versions
Version Deps Published
2.110.9 2 / 10
2.110.8 2 / 10
2.110.7 2 / 10
2.110.6 2 / 10
2.110.5 2 / 10
2.110.4 2 / 10
2.110.3 2 / 10
2.110.2 2 / 10
2.110.1 2 / 10
2.110.0 2 / 10
2.109.0 2 / 10
2.108.2 2 / 10
2.108.1 2 / 10
2.108.0 2 / 10
2.107.0 2 / 10
2.106.2 2 / 10
2.106.1 2 / 7
2.106.0 2 / 7
2.105.4 2 / 7
2.105.3 4 / 7
2.105.2 4 / 7
2.105.1 4 / 7
2.105.0 4 / 7
2.104.1 4 / 7
2.104.0 4 / 7
2.103.3 4 / 7
2.103.2 4 / 7
2.103.1 4 / 7
2.103.0 4 / 7
2.102.1 4 / 7
2.102.0 4 / 7
2.101.1 4 / 7
2.101.0 4 / 7
2.100.1 4 / 7
2.100.0 4 / 7
2.99.3 4 / 7
2.99.2 4 / 7
2.99.1 4 / 7
2.99.0 4 / 7
2.98.0 4 / 7
2.97.0 4 / 7
2.96.0 4 / 7
2.95.3 4 / 7
2.95.2 4 / 7
2.95.1 4 / 7
2.95.0 4 / 7
2.94.1 4 / 7
2.94.0 4 / 7
2.93.3 4 / 7
2.93.2 4 / 7
2.93.1 4 / 7

v2.110.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.109.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.