← Home

@supabase/storage-js

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

etienne_supamandarini

Keywords

javascripttypescriptsupabase

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Monorepo restructure dropped gitHead; SLSA provenance present as compensating control. ai
maintainer-change maintainer-removed AI (maintainer-change): Supabase consolidated publishing to GitHub Actions; maintainer list cleanup is expected. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is declared in dependencies and used implicitly via TypeScript compilation; stable FP. ai

Versions (showing 100 of 112)

Version Deps Published
2.110.9 2 / 7
2.110.8 2 / 7
2.110.7 2 / 7
2.110.6 2 / 7
2.110.5 2 / 7
2.110.4 2 / 7
2.110.3 2 / 7
2.110.2 2 / 7
2.110.1 2 / 7
2.110.0 2 / 7
2.109.0 2 / 7
2.108.2 2 / 7
2.108.1 2 / 7
2.108.0 2 / 7
2.107.0 2 / 7
2.106.2 2 / 7
2.106.1 2 / 1
2.106.0 2 / 1
2.105.4 2 / 1
2.105.3 2 / 1
2.105.2 2 / 1
2.105.1 2 / 1
2.105.0 2 / 1
2.104.0 2 / 1
2.103.3 2 / 1
2.103.2 2 / 1
2.103.1 2 / 1
2.103.0 2 / 1
2.102.1 2 / 1
2.102.0 2 / 1
2.101.1 2 / 1
2.101.0 2 / 1
2.100.1 2 / 1
2.100.0 2 / 1
2.99.3 2 / 1
2.99.2 2 / 1
2.99.1 2 / 1
2.99.0 2 / 1
2.98.0 2 / 1
2.97.0 2 / 1
2.96.0 2 / 1
2.95.3 2 / 1
2.95.2 2 / 1
2.95.1 2 / 1
2.95.0 2 / 1
2.94.1 2 / 1
2.94.0 2 / 1
2.93.3 2 / 1
2.93.2 2 / 1
2.93.1 2 / 1
2.93.0 2 / 1
2.92.0 2 / 1
2.91.2 2 / 1
2.91.1 2 / 1
2.91.0 2 / 1
2.90.1 2 / 1
2.90.0 2 / 1
2.89.0 2 / 1
2.88.0 2 / 1
2.87.3 2 / 4
2.87.2 2 / 4
2.87.1 2 / 4
2.87.0 2 / 4
2.86.2 2 / 4
2.86.1 2 / 4
2.86.0 2 / 4
2.85.0 1 / 4
2.84.0 1 / 4
2.83.0 1 / 4
2.82.0 1 / 4
2.81.1 1 / 4
2.81.0 1 / 4
2.80.0 1 / 4
2.79.0 1 / 4
2.78.0 2 / 4
2.77.0 2 / 8
2.76.1 2 / 8
2.76.0 1 / 8
2.75.1 1 / 8
2.75.0 1 / 8
2.74.0 1 / 8
2.12.2 1 / 17
2.12.1 1 / 17
2.12.0 1 / 17
2.11.1 1 / 17
2.11.0 1 / 17
2.10.5 1 / 17
2.10.4 1 / 17
2.10.3 1 / 17
2.10.2 1 / 17
2.10.1 1 / 17
2.10.0 1 / 17
2.9.1 1 / 17
2.9.0 1 / 17
2.8.0 1 / 17
2.7.3 1 / 17
2.7.2 1 / 17
2.7.1 1 / 17
2.7.0 1 / 17
2.6.0 1 / 17
Showing 100 of 112 Next page →

v2.110.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.109.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.