@vercel/hono
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:pino | AI (typosquat): Official Vercel monorepo package; name reflects hono framework adapter, not a pino typosquat. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Framework adapter; deps loaded by convention, not direct import. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): Framework adapter; deps loaded by convention, not direct import. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:ts-morph | AI (phantom-deps): Framework adapter; deps loaded by convention, not direct import. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@vercel/nft | AI (phantom-deps): Framework-scoped Vercel package loaded by convention. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:path-to-regexp | AI (phantom-deps): Framework adapter; deps loaded by convention, not direct import. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@vercel/static-config | AI (phantom-deps): Framework-scoped Vercel package loaded by convention. Stable pattern for this package. | ai |
Versions (showing 51 of 130)
| Version | Deps | Published |
|---|---|---|
| 0.2.106 | 7 / 7 | |
| 0.2.105 | 7 / 7 | |
| 0.2.104 | 7 / 7 | |
| 0.2.103 | 7 / 7 | |
| 0.2.102 | 7 / 7 | |
| 0.2.101 | 7 / 7 | |
| 0.2.100 | 7 / 7 | |
| 0.2.99 | 7 / 7 | |
| 0.2.98 | 7 / 7 | |
| 0.2.97 | 7 / 7 | |
| 0.2.96 | 7 / 7 | |
| 0.2.95 | 7 / 7 | |
| 0.2.94 | 7 / 7 | |
| 0.2.93 | 7 / 7 | |
| 0.2.92 | 7 / 7 | |
| 0.2.91 | 7 / 7 | |
| 0.2.90 | 7 / 7 | |
| 0.2.89 | 7 / 7 | |
| 0.2.88 | 7 / 7 | |
| 0.2.87 | 7 / 7 | |
| 0.2.86 | 7 / 7 | |
| 0.2.85 | 7 / 7 | |
| 0.2.84 | 7 / 7 | |
| 0.2.83 | 7 / 7 | |
| 0.2.82 | 7 / 7 | |
| 0.2.81 | 7 / 7 | |
| 0.2.80 | 7 / 7 | |
| 0.2.79 | 7 / 7 | |
| 0.2.78 | 7 / 7 | |
| 0.2.77 | 7 / 7 | |
| 0.2.76 | 7 / 9 | |
| 0.2.74 | 7 / 9 | |
| 0.2.73 | 7 / 9 | |
| 0.2.72 | 7 / 9 | |
| 0.2.71 | 7 / 9 | |
| 0.2.69 | 7 / 9 | |
| 0.2.68 | 7 / 9 | |
| 0.2.67 | 7 / 9 | |
| 0.2.66 | 7 / 9 | |
| 0.2.65 | 7 / 9 | |
| 0.2.64 | 7 / 9 | |
| 0.2.63 | 7 / 9 | |
| 0.2.62 | 7 / 9 | |
| 0.2.61 | 7 / 9 | |
| 0.2.60 | 7 / 9 | |
| 0.2.59 | 7 / 9 | |
| 0.2.58 | 7 / 9 | |
| 0.2.57 | 7 / 9 | |
| 0.2.56 | 7 / 9 | |
| 0.2.54 | 7 / 9 | |
| 0.2.53 | 7 / 9 |
v0.2.106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.105
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.104
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.103
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.102
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.101
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.