← Home

@workday/canvas-kit-mcp

MCP package for Canvas Kit

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

Verified SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

workday-canvas-kitmannycarrera4raisa.primerovaalanbsmithjaclynjessupjheddings

Keywords

canvascanvas-kitworkdaymcp

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Workday uses GitHub Actions with SLSA attestation for automated publishing; this is the expected CI/CD pattern for this org. ai

Versions (showing 100 of 109)

Version Deps Published
15.1.4 3 / 13
15.1.3 3 / 13
15.1.2 3 / 13
15.1.1 3 / 13
15.1.0 3 / 13
15.0.21 3 / 13
15.0.20 3 / 13
15.0.19 3 / 13
15.0.18 3 / 13
15.0.17 3 / 13
15.0.16 3 / 13
15.0.15 3 / 13
15.0.13 3 / 13
15.0.12 3 / 13
15.0.11 3 / 13
15.0.9 3 / 13
15.0.8 3 / 13
15.0.7 3 / 13
15.0.6 3 / 13
15.0.3 3 / 13
15.0.1 3 / 13
14.3.12 3 / 13
14.3.11 3 / 13
14.3.10 1 / 6
14.3.9 1 / 6
14.3.8 1 / 6
14.3.7 1 / 6
14.3.6 1 / 6
14.3.5 1 / 6
14.3.4 1 / 6
14.3.3 1 / 6
14.3.2 1 / 6
14.3.1 1 / 6
14.3.0 1 / 6
14.2.37 1 / 6
14.2.36 1 / 6
14.2.35 1 / 6
14.2.34 1 / 6
14.2.33 1 / 6
14.2.32 1 / 6
14.2.31 1 / 6
14.2.30 1 / 6
14.2.29 1 / 6
14.2.28 1 / 6
14.2.27 1 / 6
14.2.26 1 / 6
14.2.25 1 / 6
14.2.24 1 / 6
14.2.23 1 / 6
14.2.22 1 / 6
14.2.21 1 / 6
14.2.20 1 / 6
14.2.19 1 / 6
14.2.18 1 / 6
14.2.17 1 / 6
14.2.16 1 / 6
14.2.15 1 / 6
14.2.14 1 / 6
14.2.13 1 / 6
14.2.12 1 / 6
14.2.11 1 / 6
14.2.10 1 / 6
14.2.9 1 / 6
14.2.8 1 / 6
14.2.7 1 / 6
14.2.6 1 / 6
14.2.5 1 / 6
14.2.4 1 / 6
14.2.3 1 / 6
14.2.2 1 / 6
14.2.1 1 / 6
14.2.0 1 / 6
14.1.28 1 / 6
14.1.27 1 / 6
14.1.26 1 / 6
14.1.25 1 / 6
14.1.24 1 / 6
14.1.23 1 / 6
14.1.22 1 / 6
14.1.21 1 / 6
14.1.20 1 / 6
14.1.19 1 / 6
14.1.18 1 / 6
14.1.17 1 / 6
14.1.10 1 / 6
14.1.9 1 / 6
14.1.8 1 / 6
14.1.7 1 / 6
14.1.6 1 / 6
14.1.5 1 / 6
14.1.4 1 / 6
14.1.1 1 / 6
13.2.57 1 / 6
13.2.56 1 / 6
13.2.55 1 / 6
13.2.54 1 / 6
13.2.53 1 / 6
13.2.52 1 / 6
13.2.51 1 / 6
13.2.50 1 / 6
Showing 100 of 109 Next page →

v15.1.4

1 finding
INFO Has verified SLSA provenance attestation provenance

Published via CI/CD with a Sigstore attestation that VERIFIED against the pinned Sigstore trust root (predicate: https://slsa.dev/provenance/v1, issuer: https://token.actions.githubusercontent.com). The attestation's sha512 subject digest matches the tarball bytes we streamed, so it describes this exact artifact. This is the strongest supply chain integrity signal.

v15.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.1.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.1.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.1.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.