← Home

@walkeros/web-source-browser

43
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

alexanderkirtzel

Keywords

walkerOSwalkerOS-sourcesourcewebbrowserdomanalytics

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from personal account to GitHub Actions CI/CD is expected for this org; SLSA attestation confirms integrity. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is @walkeros/core from the same org/monorepo at matching version; not a suspicious third-party dependency. ai
source-diff obfuscated-file:dist/dev.js AI (source-diff): Standard tsup/esbuild minified bundle for the ./dev export; not obfuscated malware. ai
source-diff obfuscated-file:dist/dev.mjs AI (source-diff): Standard tsup/esbuild minified ESM bundle for the ./dev export; not obfuscated malware. ai
source-diff net-exec-file:dist/dev.js AI (source-diff): Network/exec pattern fires on bundled Zod/walkerOS code; no actual dropper behavior present. ai
source-diff net-exec-file:dist/dev.mjs AI (source-diff): Network/exec pattern fires on bundled Zod/walkerOS code; no actual dropper behavior present. ai

Versions (showing 43 of 43)

Version Deps Published
4.3.2 3 / 0
4.3.1 3 / 0
4.3.0 3 / 0
4.2.1 3 / 0
4.2.0 3 / 0
4.1.2 3 / 0
4.1.1 3 / 0
4.1.0 3 / 0
4.0.2 2 / 0
4.0.1 2 / 0
4.0.0 2 / 0
3.4.2 2 / 0
3.4.1 2 / 0
3.4.0 2 / 0
3.3.1 2 / 0
3.3.0 2 / 0
3.2.0 2 / 0
3.1.1 2 / 0
3.1.0 2 / 0
3.0.2 2 / 0
3.0.1 2 / 0
3.0.0 2 / 0
2.1.1 2 / 0
2.1.0 2 / 0
2.0.1 2 / 0
2.0.0 2 / 0
1.1.4 2 / 0
1.1.3 2 / 0
1.1.2 2 / 0
1.1.1 2 / 0
1.1.0 2 / 0
1.0.1 2 / 0
1.0.0 2 / 0
0.8.0 2 / 0
0.6.1 2 / 0
0.6.0 2 / 0
0.5.0 2 / 0
0.4.2 2 / 0
0.4.1 2 / 0
0.4.0 2 / 0
0.3.2 2 / 0
0.3.1 2 / 0
0.3.0 2 / 0

v4.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.