← Home

@taole/deploy-helper

脚本部署工具,用于将项目部署到测试环境或生产环境

18
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

yanyalongshanjianhangtw_wangaxbigerfeswqsldz

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:alibabacloud-devops-mcp-server AI (phantom-deps): Package ships the module under modules/ directory and lists it in files; phantom-dep heuristic is a false positive here. ai
dependencies unvetted-dep:node-scp AI (dependencies): SCP library is appropriate for a deploy-helper tool; stable usage across many versions. ai
dependencies unvetted-dep:alibabacloud-devops-mcp-server AI (dependencies): Alibaba Cloud DevOps integration is expected for this deployment utility targeting Alibaba Cloud environments. ai
bogus-package bogus-package AI (bogus-package): Internal/scoped deploy tool; sparse metadata is consistent with private tooling, not spam. ai
phantom-deps phantom-dep:form-data AI (phantom-deps): form-data is declared as a direct dependency in package.json; likely used transitively or indirectly via ali-oss/archiver internals. ai

Versions (showing 18 of 18)

Version Deps Published
1.0.5 4 / 0
1.0.4 4 / 0
1.0.3 6 / 0
1.0.2 7 / 0
1.0.1 7 / 0
1.0.0 7 / 0
0.7.5 6 / 0
0.7.4 6 / 0
0.7.3 6 / 0
0.7.2 6 / 0
0.7.1 6 / 0
0.7.0 6 / 0
0.6.6 6 / 0
0.6.5 6 / 0
0.6.4 6 / 0
0.6.2 6 / 0
0.6.1 6 / 0
0.6.0 6 / 0

v1.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.