@voiceflow/base-types
Voiceflow base project types
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): vf-serviceaccount is the Voiceflow org CI account with 82 approved packages; publisher migration is expected for this org. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy aligns with org-level tooling migration to vf-serviceaccount; no malicious indicators present. | ai | |
| provenance | no-provenance | AI (provenance): Voiceflow org packages consistently lack provenance; stable false positive for this publisher. | ai |
Versions (showing 51 of 308)
| Version | Deps | Published |
|---|---|---|
| 2.138.2 | 2 / 0 | |
| 2.138.1 | 2 / 0 | |
| 2.138.0 | 2 / 0 | |
| 2.137.0 | 2 / 0 | |
| 2.136.4 | 2 / 0 | |
| 2.136.1 | 2 / 0 | |
| 2.136.0 | 2 / 0 | |
| 2.135.0 | 2 / 0 | |
| 2.134.1 | 2 / 0 | |
| 2.134.0 | 2 / 0 | |
| 2.133.1 | 2 / 0 | |
| 2.133.0 | 2 / 0 | |
| 2.132.2 | 2 / 0 | |
| 2.132.1 | 2 / 0 | |
| 2.132.0 | 2 / 0 | |
| 2.131.2 | 2 / 0 | |
| 2.131.1 | 2 / 0 | |
| 2.131.0 | 2 / 0 | |
| 2.130.1 | 2 / 0 | |
| 2.130.0 | 2 / 0 | |
| 2.129.0 | 2 / 0 | |
| 2.128.2 | 2 / 0 | |
| 2.128.1 | 2 / 0 | |
| 2.128.0 | 2 / 0 | |
| 2.127.2 | 2 / 0 | |
| 2.127.1 | 2 / 0 | |
| 2.127.0 | 2 / 0 | |
| 2.126.0 | 2 / 0 | |
| 2.125.0 | 2 / 0 | |
| 2.124.0 | 2 / 0 | |
| 2.123.0 | 2 / 0 | |
| 2.122.1 | 2 / 0 | |
| 2.122.0 | 2 / 0 | |
| 2.121.4 | 2 / 0 | |
| 2.121.3 | 2 / 0 | |
| 2.121.2 | 2 / 0 | |
| 2.121.1 | 2 / 0 | |
| 2.121.0 | 2 / 0 | |
| 2.120.0 | 2 / 0 | |
| 2.119.0 | 2 / 0 | |
| 2.118.1 | 2 / 0 | |
| 2.118.0 | 2 / 0 | |
| 2.117.0 | 2 / 0 | |
| 2.116.1 | 2 / 0 | |
| 2.116.0 | 2 / 0 | |
| 2.115.0 | 2 / 0 | |
| 2.114.0 | 2 / 0 | |
| 2.113.2 | 2 / 0 | |
| 2.113.1 | 2 / 0 | |
| 2.113.0 | 2 / 0 | |
| 2.112.0 | 2 / 0 |
v2.132.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.132.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.131.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.131.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.131.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.130.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.130.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.129.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.128.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.128.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.128.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.127.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.127.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.127.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.126.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.125.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.124.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.123.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.122.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.122.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.121.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.121.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.121.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.121.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.121.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.120.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.119.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.118.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.118.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.117.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.116.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.116.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.115.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.114.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.113.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.113.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.113.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.112.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.