← Home

@workflow/astro

Astro integration for Workflow SDK

9
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@workflow/builders AI (dependencies): Same @workflow org scope as this package; consistent pattern across the monorepo dependencies. ai
maintainer-change maintainer-added AI (maintainer-change): Vercel org package published via GitHub Actions with SLSA provenance; maintainer additions are consistent with org team management. ai
phantom-deps phantom-dep:@swc/core AI (phantom-deps): SWC is a peer/transitive dep for the Astro integration; phantom-dep is a stable FP here. ai
phantom-deps phantom-dep:pathe AI (phantom-deps): Build-tool integration; pathe used transitively via config, not directly imported. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package from vercel/workflow; thin README and no keywords are cosmetic, not risk signals. ai
phantom-deps phantom-dep:@workflow/swc-plugin AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a stable FP for monorepo packages. ai
phantom-deps phantom-dep:exsolve AI (phantom-deps): Same pattern — referenced in config context, not a direct import. ai

Versions (showing 9 of 9)

Version Deps Published
4.0.8 7 / 3
4.0.7 7 / 3
4.0.6 7 / 3
4.0.5 7 / 3
4.0.4 7 / 3
4.0.3 7 / 3
4.0.2 7 / 3
4.0.1 7 / 3
4.0.0 7 / 3

v4.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.