← Home

@toiroakr/lines-db

17
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

toiroakr

Keywords

databasejsonlsqliteseed-data

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:new-function-constructor AI (semgrep): Used only as an eval-capability probe (new Function("") in try/catch), not to execute dynamic user input. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get in a Proxy get trap for camelCase aliasing — idiomatic and not obfuscatory. ai
phantom-deps phantom-dep:amaro AI (phantom-deps): amaro is declared as a runtime dep and used as a TypeScript stripper; phantom-dep heuristic false positive. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publisher with SLSA provenance attestation; legitimate automation handoff. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): tsx is a CLI runtime dependency used via bin/cli.js; not directly imported in source but legitimately required. ai

Versions (showing 17 of 17)

Version Deps Published
0.10.1 2 / 9
0.10.0 2 / 9
0.9.2 3 / 6
0.9.1 3 / 6
0.9.0 3 / 6
0.8.0 3 / 6
0.7.0 3 / 6
0.6.1 3 / 6
0.6.0 3 / 6
0.5.0 3 / 5
0.4.1 3 / 5
0.4.0 3 / 5
0.3.0 3 / 5
0.2.1 3 / 5
0.2.0 2 / 5
0.1.2 2 / 5
0.1.0 2 / 5

v0.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.