← Home

@tryghost/logging

`npm install @tryghost/logging --save`

29
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostaustin.burdineweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is superseded by Sigstore attestation for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads loggingrc config file from process root with fallback; stable config-loading pattern for this package. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): fs-extra is a declared runtime dependency; phantom-dep heuristic false positive for this package. ai

Versions (showing 29 of 29)

Version Deps Published
5.3.1 10 / 2
5.3.0 10 / 2
5.2.1 10 / 2
5.2.0 10 / 2
5.1.2 10 / 2
5.1.1 10 / 2
5.1.0 10 / 2
5.0.3 10 / 2
5.0.2 10 / 2
5.0.1 10 / 2
5.0.0 10 / 2
4.2.1 11 / 2
4.2.0 11 / 2
4.1.1 11 / 2
4.1.0 11 / 2
4.0.3 11 / 2
4.0.2 11 / 2
4.0.1 11 / 2
4.0.0 11 / 4
3.2.1 11 / 4
3.2.0 11 / 4
3.1.0 11 / 4
3.0.0 11 / 4
2.5.5 11 / 4
2.5.4 11 / 4
2.5.3 11 / 4
2.5.2 11 / 5
2.5.1 11 / 5
2.5.0 11 / 5

v5.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.