← Home

@walkeros/web-destination-plausible

Plausible web destination for walkerOS

42
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

alexanderkirtzel

Keywords

walkerOSwalkerOS-destinationdestinationwebplausibleanalytics

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-dropped AI (source-diff): Size drop consistent with monorepo refactor extracting shared code into @walkeros/core dependency. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; consistent with org-wide CI/CD adoption. ai
publish-pattern new-deps-added AI (publish-pattern): @walkeros/core is a first-party monorepo package from the same org/version; not a suspicious third-party dep. ai
source-diff net-exec-file:dist/dev.js AI (source-diff): Network calls are Plausible analytics API calls; dynamic code execution is standard module pattern from bundler output. ai
source-diff net-exec-file:dist/dev.mjs AI (source-diff): Same as CJS variant; legitimate analytics destination bundle. ai
source-diff obfuscated-file:dist/dev.js AI (source-diff): tsup-minified bundle; content is Zod + walkerOS destination code, not obfuscated malware. ai
source-diff obfuscated-file:dist/dev.mjs AI (source-diff): Same tsup-minified ESM bundle; legitimate build artifact. ai
provenance no-provenance AI (provenance): Established walkerOS monorepo package; provenance not configured but no other risk signals present. ai

Versions (showing 42 of 42)

Version Deps Published
4.3.2 2 / 1
4.3.1 2 / 1
4.3.0 2 / 1
4.2.1 2 / 1
4.2.0 2 / 1
4.1.2 2 / 1
4.1.1 2 / 1
4.1.0 2 / 1
4.0.2 1 / 1
4.0.1 1 / 1
4.0.0 1 / 1
3.4.2 1 / 1
3.4.1 1 / 1
3.4.0 1 / 1
3.3.1 1 / 1
3.3.0 1 / 1
3.2.0 1 / 1
3.1.1 1 / 1
3.1.0 1 / 1
3.0.2 1 / 1
3.0.1 1 / 1
3.0.0 1 / 1
2.1.1 1 / 1
2.1.0 1 / 1
2.0.1 1 / 1
2.0.0 1 / 1
1.0.6 1 / 1
1.0.5 1 / 0
1.0.4 1 / 0
1.0.3 1 / 0
1.0.2 1 / 0
1.0.1 1 / 0
1.0.0 1 / 0
0.8.0 1 / 0
0.6.1 1 / 0
0.6.0 1 / 0
0.5.0 1 / 0
0.4.2 1 / 0
0.4.1 1 / 0
0.4.0 1 / 0
0.3.1 1 / 0
0.3.0 1 / 0

v4.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.