← Home

@vercel/cervel

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matheussmatt.strakavercel-release-botzeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
email-domain unclaimed-email:magic.io AI (email-domain): Publisher is vercel-release-bot with SLSA provenance; stale maintainer email does not represent a realistic hijack vector for this package. ai
bogus-package bogus-package AI (bogus-package): Internal Vercel monorepo package; missing description/keywords are expected for this type of package. ai
provenance publisher-changed AI (provenance): Vercel migrated publishing to GitHub Actions CI with SLSA attestation; stable pattern for this org's packages. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainer is within Vercel org; consistent with internal team management of official @vercel/* packages. ai
npm-metadata no-description AI (npm-metadata): Internal Vercel tooling package; missing description is cosmetic, not a malware signal. ai

Versions (showing 51 of 85)

View all versions
Version Deps Published
0.1.34 1 / 3
0.1.33 1 / 3
0.1.32 1 / 3
0.1.31 1 / 3
0.1.30 1 / 3
0.1.29 1 / 3
0.1.28 1 / 3
0.1.27 1 / 3
0.1.26 1 / 3
0.1.25 1 / 3
0.1.24 1 / 3
0.1.23 1 / 3
0.1.22 1 / 3
0.1.21 1 / 3
0.1.20 1 / 3
0.1.19 1 / 3
0.1.18 1 / 3
0.1.17 1 / 3
0.1.16 1 / 3
0.1.15 1 / 3
0.1.14 1 / 3
0.1.13 1 / 3
0.1.12 1 / 3
0.1.11 1 / 3
0.1.10 1 / 3
0.1.9 1 / 3
0.1.8 1 / 3
0.1.7 1 / 3
0.1.6 1 / 3
0.1.5 1 / 3
0.1.4 1 / 3
0.1.3 1 / 3
0.1.2 1 / 3
0.1.1 1 / 3
0.1.0 1 / 3
0.0.55 1 / 4
0.0.54 1 / 4
0.0.53 1 / 4
0.0.52 1 / 4
0.0.50 1 / 4
0.0.49 1 / 4
0.0.48 1 / 4
0.0.47 1 / 4
0.0.46 1 / 4
0.0.45 1 / 4
0.0.44 1 / 4
0.0.43 1 / 4
0.0.42 1 / 4
0.0.41 1 / 4
0.0.40 1 / 4
0.0.39 1 / 4

v0.1.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.