← Home

@visactor/vutils-extension

34
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

liufangfangvisactorownerxuanhunzamhownchensiji.0517youngwindspurpose233ssfxzlixuefei.1313ray_sunxiaoluohesimaqxile611da730zhouxinyu66888zexian_chen

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; stable pattern for this VisActor org package. ai
dependencies unvetted-dep:@visactor/vdataset AI (dependencies): First-party VisActor org dependency; consistent with the package's ecosystem and stable across versions. ai

Versions (showing 34 of 34)

Version Deps Published
2.1.4 2 / 22
2.1.3 2 / 22
2.1.2 2 / 22
2.1.1 2 / 22
2.1.0 2 / 22
2.0.22 2 / 22
2.0.21 2 / 22
2.0.20 2 / 22
2.0.19 2 / 22
2.0.18 2 / 22
2.0.17 2 / 22
2.0.16 2 / 22
2.0.15 2 / 22
2.0.14 2 / 22
2.0.13 2 / 22
2.0.12 2 / 22
2.0.11 2 / 22
2.0.10 2 / 22
2.0.9 2 / 22
2.0.8 2 / 22
2.0.7 2 / 22
2.0.6 2 / 22
2.0.5 2 / 22
2.0.4 2 / 22
2.0.3 2 / 22
2.0.2 2 / 22
2.0.1 2 / 22
2.0.0 2 / 22
1.13.27 2 / 22
1.13.26 2 / 22
1.13.25 2 / 22
1.13.24 2 / 22
1.13.23 2 / 22
1.13.22 2 / 22

v2.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.