← Home

@vercel/go

26
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

matheussmatt.strakavercel-release-botzeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:got AI (typosquat): @vercel/go is the official Vercel Go runtime, not a typosquat of 'got'; scoped under verified @vercel org. ai
typosquat typosquat.levenshtein:glob AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'glob' is coincidental. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'koa' is coincidental. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'pg' is coincidental. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'qs' is coincidental. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'joi' is coincidental. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'zod' is coincidental. ai

Versions (showing 26 of 26)

Version Deps Published
3.8.0 0 / 17
3.7.1 0 / 17
3.7.0 0 / 17
3.6.0 0 / 18
3.5.0 0 / 19
3.4.7 0 / 19
3.4.6 0 / 19
3.4.5 0 / 19
3.4.4 0 / 19
3.4.3 0 / 19
3.4.2 0 / 19
3.4.1 0 / 19
3.4.0 0 / 19
3.3.5 0 / 19
3.3.4 0 / 20
3.3.3 0 / 20
3.3.2 0 / 20
3.3.1 0 / 20
3.3.0 0 / 20
3.2.4 0 / 20
3.2.3 0 / 20
3.2.2 0 / 20
3.2.1 0 / 20
3.2.0 0 / 20
3.1.3 0 / 20
3.1.2 0 / 20

v3.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.