← Home

@vercel/cli-config

5
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matheussmatt.strakavercel-release-botzeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Benign CI metadata gap on an attested, unchanged Vercel publish. ai
maintainer-change maintainer-added AI (maintainer-change): zeit-bot is a known Vercel automation account; addition is consistent with org-wide bot consolidation. ai
maintainer-change maintainer-removed AI (maintainer-change): Mass removal reflects Vercel org maintainer list cleanup, not a takeover; SLSA provenance confirms legitimate CI publish. ai
bogus-package bogus-package AI (bogus-package): Internal Vercel utility package; sparse README and no keywords are expected for org-internal tooling. ai
email-domain unclaimed-email:magic.io AI (email-domain): Package has SLSA provenance from GitHub Actions and is part of the official vercel/vercel monorepo; stale maintainer email is low risk here. ai

Versions (showing 5 of 5)

Version Deps Published
0.2.1 2 / 4
0.2.0 2 / 4
0.1.2 2 / 4
0.1.1 2 / 4
0.1.0 2 / 4

v0.2.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.