@voyantjs/storefront
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@voyantjs/availability | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@voyantjs/products | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@voyantjs/sellability | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Re-exported dependency in monorepo; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:hono | AI (phantom-deps): Re-exported dependency in monorepo; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:drizzle-orm | AI (phantom-deps): Re-exported dependency in monorepo; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@voyantjs/core | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@voyantjs/hono | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@voyantjs/extras | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@voyantjs/pricing | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; missing gitHead is superseded by Sigstore attestation for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Monorepo internal package; missing description is a style issue, not a malice indicator. | ai |
Versions (showing 51 of 223)
| Version | Deps | Published |
|---|---|---|
| 0.106.0 | 13 / 4 | |
| 0.105.0 | 13 / 4 | |
| 0.104.1 | 13 / 4 | |
| 0.104.0 | 13 / 4 | |
| 0.103.0 | 13 / 4 | |
| 0.102.0 | 13 / 4 | |
| 0.101.2 | 13 / 4 | |
| 0.101.1 | 13 / 4 | |
| 0.101.0 | 13 / 4 | |
| 0.100.0 | 13 / 4 | |
| 0.99.0 | 13 / 4 | |
| 0.98.0 | 13 / 4 | |
| 0.97.0 | 13 / 4 | |
| 0.96.0 | 13 / 4 | |
| 0.95.0 | 13 / 4 | |
| 0.94.0 | 13 / 4 | |
| 0.92.0 | 13 / 4 | |
| 0.90.0 | 13 / 4 | |
| 0.89.0 | 13 / 4 | |
| 0.88.0 | 13 / 4 | |
| 0.87.1 | 13 / 4 | |
| 0.86.0 | 13 / 4 | |
| 0.85.4 | 13 / 4 | |
| 0.85.3 | 13 / 4 | |
| 0.85.2 | 13 / 4 | |
| 0.85.1 | 13 / 4 | |
| 0.85.0 | 13 / 4 | |
| 0.84.4 | 13 / 4 | |
| 0.84.3 | 13 / 4 | |
| 0.84.2 | 13 / 4 | |
| 0.84.1 | 13 / 4 | |
| 0.84.0 | 13 / 4 | |
| 0.83.0 | 13 / 4 | |
| 0.82.1 | 13 / 4 | |
| 0.82.0 | 13 / 4 | |
| 0.81.21 | 13 / 4 | |
| 0.81.20 | 13 / 4 | |
| 0.81.19 | 13 / 4 | |
| 0.81.18 | 13 / 4 | |
| 0.81.17 | 13 / 4 | |
| 0.81.16 | 13 / 4 | |
| 0.81.15 | 13 / 4 | |
| 0.81.13 | 13 / 4 | |
| 0.81.12 | 13 / 4 | |
| 0.81.11 | 13 / 4 | |
| 0.81.9 | 13 / 4 | |
| 0.81.8 | 13 / 4 | |
| 0.81.7 | 13 / 4 | |
| 0.81.6 | 13 / 4 | |
| 0.81.5 | 13 / 4 | |
| 0.81.1 | 13 / 4 |
v0.106.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.105.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.104.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.104.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.103.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.102.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.101.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.101.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.101.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.100.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.97.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.96.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.95.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.90.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.89.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.88.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.87.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.83.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.82.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.82.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.