← Home

@upstash/box

53
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

mdoganbuggyhuntercahidardafahreddin.ozcanupstashnpmjoshtcburak-upsshannonr

Keywords

upstashboxai-agentcoding-agentclaudeasyncparallelsdkapi

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:zod AI (phantom-deps): zod is a declared runtime dependency; phantom-dep heuristic misfires here. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Scoped @upstash package; not a typosquat of koa. ai
typosquat typosquat.levenshtein:mobx AI (typosquat): Scoped @upstash package; not a typosquat of mobx. ai
typosquat typosquat.levenshtein:got AI (typosquat): Scoped @upstash package; not a typosquat of got. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @upstash package; not a typosquat of joi. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped @upstash package; not a typosquat of zod. ai

Versions (showing 53 of 53)

Version Deps Published
0.5.5 1 / 6
0.5.4 1 / 6
0.5.3 1 / 6
0.5.2 1 / 6
0.5.1 1 / 6
0.5.0 1 / 6
0.4.8 1 / 6
0.4.7 1 / 6
0.4.6 1 / 6
0.4.5 1 / 6
0.4.4 1 / 6
0.4.3 1 / 6
0.4.2 1 / 6
0.4.1 1 / 6
0.4.0 1 / 6
0.3.0 1 / 6
0.2.3 1 / 6
0.2.2 1 / 6
0.2.0 1 / 6
0.1.36 1 / 6
0.1.35 1 / 6
0.1.34 1 / 6
0.1.33 1 / 6
0.1.32 1 / 6
0.1.31 1 / 6
0.1.30 1 / 6
0.1.29 1 / 4
0.1.28 1 / 4
0.1.27 1 / 4
0.1.26 1 / 4
0.1.25 1 / 4
0.1.24 1 / 4
0.1.23 1 / 4
0.1.22 1 / 4
0.1.21 1 / 4
0.1.20 1 / 4
0.1.19 1 / 4
0.1.18 1 / 4
0.1.16 1 / 4
0.1.15 1 / 4
0.1.14 1 / 4
0.1.13 1 / 4
0.1.12 1 / 4
0.1.11 1 / 4
0.1.10 2 / 4
0.1.8 1 / 4
0.1.7 1 / 4
0.1.6 1 / 4
0.1.5 1 / 4
0.1.4 1 / 4
0.1.3 1 / 4
0.1.2 1 / 4
0.0.0 1 / 4

v0.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.