@things-factory/integration-melsec
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Large monorepo package with 1053 published versions; provenance not historically used by this publisher. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 9.2.33 | 2 / 0 | |
| 9.2.31 | 2 / 0 | |
| 9.2.30 | 2 / 0 | |
| 9.2.29 | 2 / 0 | |
| 9.2.28 | 2 / 0 | |
| 9.2.27 | 2 / 0 | |
| 9.2.25 | 2 / 0 | |
| 9.2.19 | 2 / 0 | |
| 9.2.18 | 2 / 0 | |
| 9.2.17 | 2 / 0 | |
| 8.0.92 | 2 / 0 | |
| 8.0.90 | 2 / 0 | |
| 8.0.89 | 2 / 0 | |
| 8.0.88 | 2 / 0 | |
| 8.0.87 | 2 / 0 | |
| 4.3.824 | 2 / 0 | |
| 4.3.822 | 2 / 0 | |
| 4.3.695 | 2 / 0 | |
| 4.3.689 | 2 / 0 | |
| 4.3.686 | 2 / 0 | |
| 4.3.685 | 2 / 0 | |
| 4.3.684 | 2 / 0 | |
| 4.3.682 | 2 / 0 | |
| 4.3.677 | 2 / 0 | |
| 4.3.675 | 2 / 0 | |
| 4.3.673 | 2 / 0 | |
| 4.3.672 | 2 / 0 | |
| 4.3.671 | 2 / 0 | |
| 4.3.653 | 2 / 0 | |
| 4.3.652 | 2 / 0 | |
| 4.3.616 | 2 / 0 | |
| 4.3.614 | 2 / 0 | |
| 4.3.591 | 2 / 0 | |
| 4.3.582 | 2 / 0 | |
| 4.3.581 | 2 / 0 | |
| 4.3.563 | 2 / 0 | |
| 4.3.562 | 2 / 0 | |
| 4.3.544 | 2 / 0 | |
| 4.3.536 | 2 / 0 | |
| 4.3.535 | 2 / 0 | |
| 4.3.534 | 2 / 0 | |
| 4.3.533 | 2 / 0 | |
| 4.3.526 | 2 / 0 | |
| 4.3.524 | 2 / 0 | |
| 4.3.518 | 2 / 0 | |
| 4.3.512 | 2 / 0 | |
| 4.3.511 | 2 / 0 | |
| 4.3.479 | 2 / 0 |
v9.2.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.616
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.614
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.591
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.582
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.581
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.563
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.562
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.544
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.536
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.535
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.534
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.533
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.526
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.524
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.518
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.512
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.511
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.479
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.