← Home

@sveltejs/kit

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

rich_harrissvelte-adminconduitry

Keywords

frameworkofficialsveltesveltekitvite

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Documented SvelteKit config sync; stable benign postinstall. ai
typosquat typosquat.levenshtein:vite AI (typosquat): Official @sveltejs scoped package; Levenshtein match to 'vite' is a false positive. ai
typosquat typosquat.levenshtein:got AI (typosquat): Official @sveltejs scoped package; Levenshtein match to 'got' is a false positive. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Official @sveltejs scoped package; Levenshtein match to 'koa' is a false positive. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used for legitimate response property access in load_data.js; not obfuscation. ai
phantom-deps phantom-dep:@types/cookie AI (phantom-deps): @types/cookie is a type-only dependency used for TypeScript declarations, not a runtime import. ai
semgrep semgrep:env-spread AI (semgrep): process.env spread into Worker env is standard Node.js worker isolation pattern in SvelteKit's fork utility. ai

Versions (showing 8 of 8)

Version Deps Published
2.70.1 12 / 13
2.70.0 12 / 13
2.69.3 12 / 13
2.69.2 12 / 13
2.69.1 12 / 13
2.69.0 12 / 13
2.61.0 12 / 13
2.60.1 12 / 12

v2.70.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.70.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.69.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.69.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.69.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.69.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.61.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.60.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.