← Home

@vitus-labs/tools-rollup

[Rollup](https://rollupjs.org)-powered build tool for TypeScript libraries.

21
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

vitbokisch

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Package has SLSA provenance attestation which supersedes gitHead as a supply-chain integrity signal. ai
dependencies unvetted-dep:rollup-plugin-api-extractor AI (dependencies): Rollup build tooling package; this plugin is a legitimate peer for its documented use case. ai
dependencies unvetted-dep:rollup-plugin-tsconfig-paths AI (dependencies): Rollup build tooling package; tsconfig-paths plugin is a legitimate dependency for its documented use case. ai
dependencies unvetted-dep:rollup-plugin-typescript-paths AI (dependencies): Rollup build tooling package; typescript-paths plugin is a legitimate dependency for its documented use case. ai
phantom-deps phantom-dep:@microsoft/api-extractor AI (phantom-deps): Referenced in config files for API extraction; stable false positive for this rollup tooling package. ai
phantom-deps phantom-dep:@rollup/plugin-typescript AI (phantom-deps): Rollup plugin loaded by convention in build config; stable false positive. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit runtime dependency for TypeScript output; stable false positive for this build tooling package. ai
phantom-deps phantom-dep:rollup-plugin-tsconfig-paths AI (phantom-deps): Rollup plugin referenced in config files; stable false positive. ai
phantom-deps phantom-dep:rollup-plugin-typescript-paths AI (phantom-deps): Rollup plugin referenced in config files; stable false positive. ai
phantom-deps phantom-dep:typescript-transform-paths AI (phantom-deps): TypeScript transform plugin referenced in config; stable false positive. ai
phantom-deps phantom-dep:find-up AI (phantom-deps): Referenced in config files as expected for a build tool; stable false positive. ai
phantom-deps phantom-dep:lodash-es AI (phantom-deps): Referenced in config files; stable false positive for this build tooling package. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Framework-scoped type package loaded by convention; stable false positive. ai

Versions (showing 21 of 21)

Version Deps Published
2.4.0 20 / 3
2.3.1 20 / 3
2.3.0 21 / 3
2.2.0 21 / 3
2.1.0 21 / 3
2.0.0 21 / 3
1.15.5 21 / 3
1.15.4 21 / 3
1.15.3 21 / 3
1.15.2 21 / 3
1.15.1 21 / 3
1.15.0 21 / 3
1.14.0 21 / 3
1.13.0 21 / 3
1.12.0 21 / 3
1.11.0 21 / 3
1.10.0 21 / 3
1.9.0 21 / 3
1.7.0 21 / 3
1.6.0 21 / 3
1.5.1 21 / 3

v2.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.3

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.2

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.