@techsee/techsee-media-service
Techsee Media Service
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): TechSee org package with active publishing history; new maintainer appears to be internal team addition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): TechSee org internal maintainer rotation; new publisher tsadmn has clean track record across 7 approved packages. | ai | |
| dependencies | unvetted-dep:@techsee/techsee-common | AI (dependencies): First-party TechSee monorepo dependency; stable pattern across all versions of this package. | ai | |
| provenance | no-provenance | AI (provenance): Established org package; provenance not used across this publisher's ecosystem. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Preinstall runs only lint/audit tooling with || true fallback; stable pattern across this package's many versions. | ai |
Versions (showing 51 of 105)
| Version | Deps | Published |
|---|---|---|
| 26.184.0 | 5 / 43 | |
| 26.183.0 | 5 / 43 | |
| 26.182.0 | 5 / 43 | |
| 26.168.0 | 5 / 43 | |
| 26.166.0 | 5 / 43 | |
| 26.165.0 | 5 / 43 | |
| 26.161.0 | 5 / 43 | |
| 26.160.0 | 5 / 43 | |
| 26.159.0 | 5 / 43 | |
| 26.158.0 | 5 / 43 | |
| 26.157.0 | 5 / 43 | |
| 26.156.0 | 5 / 43 | |
| 26.155.0 | 5 / 43 | |
| 26.153.0 | 5 / 43 | |
| 26.152.0 | 5 / 43 | |
| 26.151.0 | 5 / 43 | |
| 26.150.0 | 5 / 43 | |
| 26.149.0 | 5 / 43 | |
| 26.147.0 | 5 / 43 | |
| 26.146.0 | 5 / 43 | |
| 26.144.0 | 5 / 43 | |
| 26.142.0 | 5 / 43 | |
| 26.141.0 | 5 / 43 | |
| 26.139.0 | 5 / 43 | |
| 26.138.0 | 5 / 43 | |
| 26.137.0 | 5 / 43 | |
| 26.136.0 | 5 / 43 | |
| 26.135.0 | 5 / 43 | |
| 26.134.0 | 5 / 43 | |
| 26.132.0 | 5 / 43 | |
| 26.128.0 | 5 / 43 | |
| 26.127.0 | 5 / 43 | |
| 26.125.0 | 5 / 43 | |
| 26.124.0 | 5 / 43 | |
| 26.121.0 | 5 / 43 | |
| 26.120.0 | 5 / 43 | |
| 26.119.0 | 5 / 43 | |
| 26.118.0 | 5 / 43 | |
| 26.116.0 | 5 / 43 | |
| 26.115.0 | 5 / 43 | |
| 26.113.0 | 5 / 43 | |
| 26.111.0 | 5 / 43 | |
| 26.110.0 | 5 / 43 | |
| 26.109.0 | 5 / 43 | |
| 26.107.0 | 5 / 43 | |
| 26.106.0 | 5 / 43 | |
| 26.104.0 | 5 / 43 | |
| 26.103.0 | 5 / 43 | |
| 26.102.0 | 5 / 43 | |
| 26.101.0 | 5 / 43 | |
| 26.99.0 | 5 / 43 |
v26.184.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.183.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.142.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.141.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.128.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.127.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.121.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.119.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.118.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.115.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.113.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.107.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.