@willbooster/wbfy
A tool for applying WillBooster's conventional configures to npm packages
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:minimal-promise-pool | AI (dependencies): minimal-promise-pool is a small promise concurrency utility with no known advisories or malware signals; its use in this tooling package is benign. | ai | |
| phantom-deps | phantom-dep:@willbooster/shared-lib | AI (phantom-deps): Same-org package used in config/template files; wbfy is a configuration tool that references packages without directly importing them. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@willbooster/shared-lib-node | AI (phantom-deps): Same-org package used in config/template files; consistent with wbfy's role as a configuration management tool. | ai | |
| phantom-deps | phantom-dep:lodash.clonedeep | AI (phantom-deps): Referenced in config files but not directly imported; consistent with wbfy's configuration template management role. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:deepmerge | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:fast-glob | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:libsodium | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:smol-toml | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:@octokit/core | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:libsodium-wrappers | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:fastest-levenshtein | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:minimal-promise-pool | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:simple-git | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai |
Versions (showing 100 of 124)
| Version | Deps | Published |
|---|---|---|
| 1.9.16 | 15 / 20 | |
| 1.9.15 | 15 / 20 | |
| 1.9.14 | 15 / 20 | |
| 1.9.13 | 15 / 20 | |
| 1.9.12 | 15 / 20 | |
| 1.9.11 | 15 / 20 | |
| 1.9.10 | 15 / 20 | |
| 1.9.9 | 15 / 20 | |
| 1.9.8 | 15 / 20 | |
| 1.9.7 | 15 / 20 | |
| 1.9.6 | 15 / 20 | |
| 1.9.5 | 15 / 20 | |
| 1.9.4 | 15 / 20 | |
| 1.9.3 | 15 / 20 | |
| 1.9.2 | 15 / 20 | |
| 1.9.1 | 15 / 20 | |
| 1.9.0 | 15 / 20 | |
| 1.8.8 | 15 / 20 | |
| 1.8.7 | 15 / 20 | |
| 1.8.6 | 15 / 20 | |
| 1.8.5 | 15 / 20 | |
| 1.8.4 | 15 / 20 | |
| 1.8.3 | 15 / 20 | |
| 1.8.2 | 15 / 20 | |
| 1.8.1 | 15 / 20 | |
| 1.8.0 | 15 / 20 | |
| 1.7.10 | 15 / 20 | |
| 1.7.9 | 15 / 20 | |
| 1.7.8 | 15 / 20 | |
| 1.7.7 | 15 / 20 | |
| 1.7.6 | 15 / 20 | |
| 1.7.5 | 15 / 20 | |
| 1.7.4 | 15 / 20 | |
| 1.7.3 | 15 / 20 | |
| 1.7.2 | 15 / 20 | |
| 1.7.1 | 15 / 20 | |
| 1.7.0 | 15 / 20 | |
| 1.6.20 | 15 / 20 | |
| 1.6.19 | 15 / 20 | |
| 1.6.18 | 15 / 20 | |
| 1.6.17 | 15 / 20 | |
| 1.6.16 | 15 / 20 | |
| 1.6.15 | 15 / 20 | |
| 1.6.14 | 15 / 20 | |
| 1.6.13 | 15 / 20 | |
| 1.6.12 | 15 / 20 | |
| 1.6.11 | 15 / 20 | |
| 1.6.10 | 15 / 20 | |
| 1.6.9 | 15 / 20 | |
| 1.6.8 | 15 / 20 | |
| 1.6.7 | 15 / 20 | |
| 1.6.6 | 15 / 20 | |
| 1.6.5 | 15 / 20 | |
| 1.6.4 | 15 / 20 | |
| 1.6.3 | 15 / 20 | |
| 1.6.2 | 15 / 19 | |
| 1.6.1 | 15 / 19 | |
| 1.6.0 | 15 / 19 | |
| 1.5.4 | 15 / 19 | |
| 1.5.3 | 15 / 19 | |
| 1.5.2 | 15 / 19 | |
| 1.5.1 | 15 / 19 | |
| 1.5.0 | 15 / 19 | |
| 1.4.35 | 15 / 19 | |
| 1.4.34 | 15 / 19 | |
| 1.4.33 | 15 / 19 | |
| 1.4.32 | 15 / 19 | |
| 1.4.31 | 15 / 19 | |
| 1.4.30 | 15 / 19 | |
| 1.4.29 | 15 / 19 | |
| 1.4.28 | 15 / 19 | |
| 1.4.27 | 15 / 19 | |
| 1.4.26 | 15 / 19 | |
| 1.4.25 | 15 / 19 | |
| 1.4.24 | 15 / 19 | |
| 1.4.23 | 15 / 19 | |
| 1.4.22 | 15 / 19 | |
| 1.4.21 | 15 / 19 | |
| 1.4.20 | 15 / 19 | |
| 1.4.19 | 15 / 19 | |
| 1.4.18 | 15 / 19 | |
| 1.4.17 | 15 / 19 | |
| 1.4.16 | 15 / 19 | |
| 1.4.15 | 15 / 19 | |
| 1.4.14 | 15 / 19 | |
| 1.4.13 | 15 / 19 | |
| 1.4.12 | 15 / 19 | |
| 1.4.11 | 15 / 19 | |
| 1.4.10 | 15 / 19 | |
| 1.4.9 | 15 / 22 | |
| 1.4.8 | 15 / 22 | |
| 1.4.7 | 15 / 22 | |
| 1.4.6 | 15 / 22 | |
| 1.4.5 | 15 / 22 | |
| 1.4.4 | 15 / 22 | |
| 1.4.3 | 15 / 22 | |
| 1.4.2 | 15 / 22 | |
| 1.4.1 | 15 / 22 | |
| 1.4.0 | 15 / 22 | |
| 1.3.9 | 15 / 22 |
v1.9.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.