← Home

@tryghost/mg-substack

23
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is a minor metadata gap, not a supply chain risk for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Ghost Foundation monorepo; infrequent publishes are normal for migration utility packages. SLSA attestation confirms CI/CD integrity. ai
dependencies unvetted-dep:@tryghost/debug AI (dependencies): First-party Ghost Foundation package; stable dependency across this package's versions. ai
provenance no-provenance AI (provenance): Ghost Foundation monorepo package; no provenance is consistent across all their published packages. ai

Versions (showing 23 of 23)

Version Deps Published
1.8.0 10 / 1
1.7.0 10 / 1
1.6.0 9 / 1
1.5.0 9 / 1
1.4.0 10 / 1
1.3.3 10 / 1
1.3.2 10 / 1
1.3.1 10 / 1
1.3.0 10 / 1
1.2.0 10 / 1
1.1.0 11 / 1
1.0.0 11 / 1
0.12.0 11 / 1
0.11.0 11 / 1
0.10.0 11 / 1
0.9.2 11 / 1
0.9.1 11 / 1
0.9.0 11 / 1
0.8.10 11 / 3
0.8.9 11 / 3
0.8.8 11 / 3
0.8.7 11 / 3
0.8.6 11 / 3

v1.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.