← Home

@yao-pkg/pkg-fetch

29
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

roberts_lando

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; legitimate automation pattern for this package. ai
semgrep semgrep:env-spread AI (semgrep): Build tool passes env to subprocess for Node.js compilation; standard pattern, not exfiltration. ai
semgrep semgrep:child-process-import AI (semgrep): pkg-fetch is a build tool that compiles Node.js binaries; child_process use is inherent to its function. ai

Versions (showing 29 of 29)

Version Deps Published
3.6.4 6 / 19
3.6.3 7 / 20
3.6.2 7 / 20
3.6.1 7 / 20
3.5.34 7 / 20
3.5.33 7 / 20
3.5.32 7 / 20
3.5.31 7 / 20
3.5.30 7 / 20
3.5.29 7 / 20
3.5.28 7 / 20
3.5.27 7 / 20
3.5.26 7 / 20
3.5.25 7 / 20
3.5.24 7 / 20
3.5.23 7 / 20
3.5.22 7 / 20
3.5.21 7 / 20
3.5.20 7 / 20
3.5.19 7 / 20
3.5.18 7 / 20
3.5.17 7 / 20
3.5.16 7 / 20
3.5.15 7 / 20
3.5.14 8 / 21
3.5.13 8 / 21
3.5.12 8 / 21
3.5.11 8 / 21
3.5.10 8 / 21

v3.5.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.5.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.