← Home

@wxn0brp/db-storage-dir

27
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

wxn0brp

Keywords

valtheravaltheradbvdb-adapter

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD with SLSA attestation; legitimate and expected for this package. ai

Versions (showing 27 of 27)

Version Deps Published
0.111.2 0 / 6
0.111.1 0 / 6
0.111.0 0 / 6
0.110.2 0 / 6
0.110.1 0 / 6
0.110.0 0 / 5
0.102.0 0 / 5
0.101.1 0 / 5
0.101.0 0 / 5
0.100.0 1 / 4
0.90.0 1 / 4
0.2.5 1 / 4
0.2.4 1 / 4
0.2.3 1 / 4
0.2.2 1 / 4
0.2.1 1 / 4
0.2.0 1 / 4
0.1.8 1 / 4
0.1.7 1 / 4
0.1.6 1 / 4
0.1.5 1 / 4
0.1.4 1 / 4
0.1.3 1 / 4
0.1.2 1 / 4
0.1.1 2 / 3
0.1.0 2 / 3
0.0.1 2 / 3

v0.111.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.111.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.111.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.110.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.