← Home

@vercel/frameworks

78
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

matheussmatt.strakavercel-release-botzeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Vercel migrated to GitHub Actions CI publishing with SLSA attestation; change is org-wide and legitimate. ai
provenance slsa-provenance AI (provenance): SLSA provenance attestation confirms release from official vercel/vercel repo. ai
publish-pattern new-deps-added AI (publish-pattern): smol-toml is a well-known, clean TOML library replacing @iarna/toml; not a suspicious addition. ai

Versions (showing 78 of 78)

Version Deps Published
3.30.7 3 / 6
3.30.6 3 / 6
3.30.5 3 / 6
3.30.4 3 / 6
3.30.3 3 / 6
3.30.2 3 / 6
3.30.1 3 / 6
3.30.0 3 / 6
3.29.1 3 / 6
3.29.0 3 / 6
3.28.1 3 / 6
3.28.0 3 / 6
3.27.0 3 / 6
3.26.1 3 / 6
3.26.0 3 / 6
3.25.1 3 / 6
3.25.0 3 / 7
3.24.2 3 / 8
3.24.1 3 / 8
3.24.0 3 / 8
3.23.0 3 / 8
3.22.0 3 / 8
3.21.1 3 / 8
3.21.0 3 / 8
3.20.0 3 / 8
3.19.1 3 / 8
3.19.0 3 / 8
3.18.0 3 / 8
3.17.1 3 / 8
3.17.0 3 / 8
3.16.1 3 / 8
3.16.0 3 / 8
3.15.7 3 / 8
3.15.6 3 / 8
3.15.5 3 / 8
3.15.4 3 / 8
3.15.3 3 / 8
3.15.2 3 / 8
3.15.1 3 / 8
3.15.0 3 / 8
3.14.1 3 / 8
3.14.0 3 / 8
3.13.0 3 / 8
3.12.0 3 / 8
3.11.1 3 / 8
3.11.0 3 / 8
3.10.0 3 / 8
3.9.3 3 / 8
3.9.2 3 / 8
3.9.1 3 / 8
3.9.0 3 / 8
3.8.5 3 / 8
3.8.4 3 / 8
3.8.3 3 / 8
3.8.2 3 / 8
3.8.1 3 / 8
3.8.0 3 / 8
3.7.7 3 / 8
3.7.6 3 / 8
3.7.5 3 / 8
3.7.4 3 / 8
3.7.3 3 / 8
3.7.2 3 / 8
3.7.1 3 / 8
3.7.0 3 / 8
3.6.4 3 / 8
3.6.3 3 / 8
3.6.2 3 / 8
3.6.1 3 / 8
3.6.0 3 / 8
3.5.0 3 / 8
3.4.0 3 / 8
3.3.1 3 / 8
3.3.0 3 / 8
3.2.0 3 / 8
3.1.1 3 / 8
3.1.0 3 / 8
3.0.3 3 / 8

v3.30.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.30.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.30.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.30.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.30.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.30.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.