← Home

@workflow/nitro

Nitro integration for Workflow SDK

9
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@workflow/core AI (phantom-deps): Same-org monorepo dep; referenced in config rather than direct import is expected for this package type. ai
phantom-deps phantom-dep:@workflow/swc-plugin AI (phantom-deps): Same-org monorepo dep; config-level reference is expected for build integration packages. ai
phantom-deps phantom-dep:exsolve AI (phantom-deps): Config-referenced dep in a build integration package; stable false positive for this package. ai
phantom-deps phantom-dep:@swc/core AI (phantom-deps): Config-referenced build dep; stable false positive for this build integration package. ai
bogus-package bogus-package AI (bogus-package): Cosmetic signals (no keywords, sparse README) are expected for internal SDK integration packages in a monorepo. ai

Versions (showing 9 of 9)

Version Deps Published
4.0.9 8 / 4
4.0.8 8 / 4
4.0.7 8 / 4
4.0.6 8 / 4
4.0.5 8 / 4
4.0.4 8 / 4
4.0.3 8 / 4
4.0.2 8 / 4
4.0.1 8 / 4

v4.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.