← Home

@treeship/core-wasm

WebAssembly bindings for Treeship cryptographic verification. Runs anywhere WASM runs: Node, browser, Vercel Edge, Cloudflare Workers, AWS Lambda.

23
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

amit.shrivastavazerker1

Keywords

treeshipattestationverificationwasmwebassemblyed25519merklereceipts

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from manual publish (zerker1) to GitHub Actions CI/CD with SLSA attestation; expected and documented pattern. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI with Sigstore attestation; stable positive signal for this package. ai

Versions (showing 23 of 23)

Version Deps Published
0.16.0 0 / 0
0.15.0 0 / 0
0.14.0 0 / 0
0.13.0 0 / 0
0.12.0 0 / 0
0.11.2 0 / 0
0.11.1 0 / 0
0.11.0 0 / 0
0.10.4 0 / 0
0.10.3 0 / 0
0.10.2 0 / 0
0.10.1 0 / 0
0.10.0 0 / 0
0.9.11 0 / 0
0.9.10 0 / 0
0.9.9 0 / 0
0.9.8 0 / 0
0.9.7 0 / 0
0.9.6 0 / 0
0.9.5 0 / 0
0.9.4 0 / 0
0.9.3 0 / 0
0.9.2 0 / 0

v0.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.