@supernova-studio/client
Supernova Data Models
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Flagged line is a test fixture string for directory traversal validation, not actual /etc/passwd access. | ai | |
| phantom-deps | phantom-dep:y-protocols | AI (phantom-deps): y-protocols is a peer/transitive dep of yjs ecosystem; phantom detection is a stable false positive here. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): 816-version history and 2 approved dependents indicate legitimate active SDK; single dormancy gap is not anomalous. | ai | |
| phantom-deps | phantom-dep:yjs | AI (phantom-deps): yjs is a declared runtime dep used transitively; phantom-dep heuristic fires but it's a legitimate dependency. | ai | |
| phantom-deps | phantom-dep:queue-promise | AI (phantom-deps): queue-promise is a declared runtime dep; phantom-dep heuristic is a false positive for this package. | ai |
Versions (showing 51 of 170)
| Version | Deps | Published |
|---|---|---|
| 1.96.7 | 9 / 5 | |
| 1.96.6 | 7 / 2 | |
| 1.96.5 | 7 / 2 | |
| 1.96.4 | 7 / 2 | |
| 1.96.3 | 7 / 2 | |
| 1.96.2 | 7 / 2 | |
| 1.96.1 | 7 / 2 | |
| 1.96.0 | 7 / 2 | |
| 1.95.5 | 7 / 2 | |
| 1.95.4 | 7 / 2 | |
| 1.95.3 | 7 / 2 | |
| 1.95.2 | 7 / 2 | |
| 1.95.1 | 7 / 2 | |
| 1.95.0 | 7 / 2 | |
| 1.94.1 | 7 / 2 | |
| 1.94.0 | 7 / 2 | |
| 1.93.0 | 7 / 2 | |
| 1.92.3 | 7 / 2 | |
| 1.92.2 | 7 / 2 | |
| 1.92.1 | 7 / 2 | |
| 1.92.0 | 7 / 2 | |
| 1.91.0 | 7 / 2 | |
| 1.90.7 | 7 / 2 | |
| 1.90.6 | 7 / 2 | |
| 1.90.5 | 7 / 2 | |
| 1.90.4 | 7 / 2 | |
| 1.90.3 | 7 / 2 | |
| 1.90.2 | 7 / 2 | |
| 1.90.1 | 7 / 2 | |
| 1.90.0 | 7 / 2 | |
| 1.89.0 | 7 / 2 | |
| 1.88.2 | 7 / 2 | |
| 1.88.1 | 7 / 2 | |
| 1.88.0 | 7 / 2 | |
| 1.87.11 | 7 / 2 | |
| 1.87.10 | 7 / 2 | |
| 1.87.9 | 7 / 2 | |
| 1.87.8 | 7 / 2 | |
| 1.87.7 | 7 / 2 | |
| 1.87.6 | 7 / 2 | |
| 1.87.5 | 7 / 2 | |
| 1.87.4 | 7 / 2 | |
| 1.87.3 | 7 / 2 | |
| 1.87.2 | 7 / 2 | |
| 1.87.1 | 7 / 2 | |
| 1.87.0 | 6 / 2 | |
| 1.86.0 | 6 / 2 | |
| 1.85.1 | 6 / 2 | |
| 1.85.0 | 6 / 2 | |
| 1.84.1 | 6 / 2 | |
| 1.84.0 | 6 / 2 |
v1.87.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.86.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.85.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.85.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.