← Home

@tryghost/bookshelf-plugins

`npm install @tryghost/bookshelf-plugins --save`

26
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostaustin.burdineweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; missing gitHead is a cosmetic metadata gap, not a supply chain risk for this package. ai
bogus-package bogus-package AI (bogus-package): Intentional thin aggregator re-exporting sibling @tryghost/bookshelf-* plugins; tiny payload and empty main are by design. ai

Versions (showing 26 of 26)

Version Deps Published
2.3.5 10 / 1
2.3.4 10 / 1
2.3.3 10 / 1
2.3.2 10 / 1
2.3.1 10 / 1
2.3.0 10 / 1
2.2.4 10 / 1
2.2.3 10 / 1
2.2.2 10 / 1
2.2.1 10 / 1
2.2.0 10 / 1
2.1.0 10 / 1
2.0.3 10 / 1
2.0.2 10 / 1
2.0.1 10 / 1
2.0.0 10 / 3
1.2.1 10 / 3
1.2.0 10 / 3
1.1.0 10 / 3
1.0.0 10 / 3
0.6.33 10 / 3
0.6.32 10 / 3
0.6.31 10 / 3
0.6.30 10 / 3
0.6.29 10 / 3
0.6.28 10 / 3

v2.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.