← Home

@turbopuffer/turbopuffer

40
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

sirupsenjlimorgangallantbenesch-turbopuffer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate org-level automation change. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org moving to automated CI publishing; no signs of hostile takeover. ai

Versions (showing 40 of 40)

Version Deps Published
2.6.0 2 / 0
2.5.1 2 / 0
2.5.0 2 / 0
2.4.0 2 / 0
2.3.0 2 / 0
2.2.0 2 / 0
2.1.0 2 / 0
2.0.0 2 / 0
1.22.0 2 / 0
1.21.0 2 / 0
1.20.0 2 / 0
1.19.0 2 / 0
1.18.0 2 / 0
1.17.0 2 / 0
1.16.0 2 / 0
1.15.2 2 / 0
1.15.1 2 / 0
1.15.0 2 / 0
1.14.10 2 / 0
1.14.9 2 / 0
1.14.8 2 / 0
1.14.7 2 / 0
1.14.6 2 / 0
1.14.5 2 / 0
1.14.4 2 / 0
1.14.3 2 / 0
1.10.0 2 / 0
1.9.1 2 / 0
1.9.0 2 / 0
1.8.0 2 / 0
1.7.0 2 / 0
1.6.0 2 / 0
1.5.1 2 / 0
1.5.0 2 / 0
1.3.0 2 / 0
1.2.1 2 / 0
1.2.0 2 / 0
1.1.1 2 / 0
1.1.0 2 / 0
1.0.0 2 / 0

v2.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.