← Home

@tryghost/bookshelf-pagination

`npm install @tryghost/bookshelf-pagination --save`

26
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostaustin.burdineweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Package has SLSA provenance attestation via CI/CD; missing gitHead is a minor metadata gap, not a supply chain risk. ai
maintainer-change maintainer-added AI (maintainer-change): Ghost Foundation org package; new maintainers consistent with org team expansion, not a takeover signal. ai
provenance no-provenance AI (provenance): Ghost Foundation packages consistently lack Sigstore provenance; stable false positive for this org. ai
dependencies unvetted-dep:@tryghost/tpl AI (dependencies): First-party Ghost Foundation sibling package; stable false positive for this package. ai

Versions (showing 26 of 26)

Version Deps Published
2.3.5 3 / 4
2.3.4 3 / 4
2.3.3 3 / 4
2.3.2 3 / 4
2.3.1 3 / 4
2.3.0 3 / 4
2.2.4 3 / 4
2.2.3 3 / 4
2.2.2 3 / 4
2.2.1 3 / 4
2.2.0 3 / 4
2.1.0 3 / 4
2.0.3 3 / 1
2.0.2 3 / 1
2.0.1 3 / 1
2.0.0 3 / 3
1.2.1 3 / 3
1.2.0 3 / 3
1.1.0 3 / 3
1.0.0 3 / 3
0.1.57 3 / 3
0.1.56 3 / 3
0.1.55 3 / 3
0.1.54 3 / 4
0.1.53 3 / 4
0.1.52 3 / 4

v2.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.