← Home

@wundergraph/cosmo-connect

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

gausiegmasgraspepolsuvijsuryadavidwgthisisnithinwilson.wundergraph

Keywords

wundergraphconnectclientwundergraph-cosmo

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/notifications/events_pb.js AI (source-diff): protoc-gen-es base64 fileDescriptor; benign generated code. ai
source-diff encoded-string-file:dist/node/v1/node_pb.js AI (source-diff): protoc-gen-es base64 fileDescriptor; benign generated code. ai
source-diff encoded-string-file:dist/platform/v1/platform_pb.js AI (source-diff): protoc-gen-es base64 fileDescriptor; benign generated code. ai
source-diff encoded-string-file:dist/common/common_pb.js AI (source-diff): protoc-gen-es base64 fileDescriptor, not a payload; stable for generated pb.js files. ai
source-diff encoded-string-file:dist/graphqlmetrics/v1/graphqlmetrics_pb.js AI (source-diff): protoc-gen-es base64 fileDescriptor; benign generated code. ai
provenance publisher-changed AI (provenance): Migration from manual publish to GitHub Actions CI/CD; provenance attested via SLSA. ai
phantom-deps phantom-dep:@connectrpc/connect-query AI (phantom-deps): Declared runtime dep used in generated Connect client code; not directly imported in source but legitimately required. ai

Versions (showing 51 of 192)

View all versions
Version Deps Published
0.155.2 2 / 2
0.155.1 2 / 2
0.155.0 2 / 2
0.154.0 2 / 2
0.153.3 2 / 2
0.151.0 2 / 2
0.150.0 2 / 2
0.149.0 2 / 2
0.148.0 2 / 2
0.146.0 2 / 2
0.145.0 2 / 2
0.144.0 2 / 2
0.143.0 2 / 2
0.142.1 2 / 2
0.142.0 2 / 2
0.141.0 2 / 2
0.140.0 2 / 2
0.139.0 2 / 2
0.138.0 2 / 2
0.137.0 2 / 2
0.136.0 2 / 2
0.135.0 2 / 2
0.134.0 2 / 2
0.133.0 2 / 2
0.132.0 2 / 2
0.131.0 2 / 2
0.130.0 2 / 2
0.129.0 2 / 2
0.128.0 2 / 2
0.127.3 2 / 2
0.127.2 2 / 2
0.127.1 2 / 2
0.127.0 2 / 2
0.126.0 2 / 2
0.125.0 2 / 2
0.124.0 2 / 2
0.123.0 2 / 2
0.122.0 2 / 2
0.121.0 2 / 2
0.120.0 2 / 2
0.119.1 2 / 2
0.119.0 2 / 2
0.118.0 2 / 2
0.117.0 2 / 2
0.116.0 2 / 2
0.115.2 2 / 2
0.115.1 2 / 2
0.115.0 2 / 2
0.114.0 2 / 2
0.113.0 2 / 2
0.112.0 2 / 2

v0.155.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.155.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.155.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.154.0

6 findings
HIGH Long encoded string in modified file: dist/common/common_pb.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/notifications/events_pb.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/graphqlmetrics/v1/graphqlmetrics_pb.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/node/v1/node_pb.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/platform/v1/platform_pb.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.