@vertz/core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | slsa-provenance | AI (provenance): Package consistently published with SLSA provenance attestation; strong supply chain integrity signal. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @vertz/core is a scoped framework package, not a typosquat of cors; the name similarity is coincidental. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 0.2.80 | 1 / 0 | |
| 0.2.78 | 1 / 0 | |
| 0.2.76 | 1 / 0 | |
| 0.2.75 | 1 / 0 | |
| 0.2.74 | 1 / 0 | |
| 0.2.73 | 1 / 0 | |
| 0.2.71 | 1 / 0 | |
| 0.2.70 | 1 / 0 | |
| 0.2.68 | 1 / 0 | |
| 0.2.67 | 1 / 0 | |
| 0.2.66 | 1 / 0 | |
| 0.2.64 | 1 / 0 | |
| 0.2.63 | 1 / 0 | |
| 0.2.62 | 1 / 0 | |
| 0.2.61 | 1 / 0 | |
| 0.2.60 | 1 / 0 | |
| 0.2.59 | 1 / 0 | |
| 0.2.55 | 1 / 0 | |
| 0.1.0 | 1 / 4 | |
| 0.0.2 | 1 / 4 |
v0.2.80
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.78
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.76
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.75
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.74
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.73
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.71
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.70
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.68
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.67
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.66
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.64
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.63
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.62
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.61
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.60
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.59
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.55
2 findingsPackage name '@vertz/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.