← Home

@zipbul/gildash

74
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

parkrevil

Keywords

typescriptindexercode-analysisdependency-graphbun

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:oxc-walker AI (phantom-deps): oxc-walker is a declared runtime dep used via build/config; phantom-dep heuristic fires incorrectly here. ai
phantom-deps phantom-dep:@ast-grep/napi AI (phantom-deps): Declared runtime dep used via config; stable false positive for this package. ai
phantom-deps phantom-dep:comment-parser AI (phantom-deps): Declared runtime dep; phantom-dep heuristic misfires on config-referenced imports. ai

Versions (showing 74 of 74)

Version Deps Published
0.40.0 7 / 11
0.39.1 7 / 11
0.39.0 7 / 11
0.38.0 7 / 10
0.37.0 7 / 9
0.36.0 7 / 9
0.35.0 7 / 9
0.34.3 7 / 9
0.34.2 7 / 9
0.34.1 7 / 9
0.34.0 7 / 9
0.33.0 7 / 9
0.32.0 7 / 9
0.31.0 7 / 9
0.30.0 7 / 9
0.29.0 7 / 9
0.28.0 7 / 9
0.27.1 7 / 9
0.27.0 7 / 9
0.26.1 7 / 9
0.26.0 7 / 9
0.25.0 7 / 9
0.24.5 7 / 9
0.24.4 7 / 9
0.24.3 7 / 9
0.24.2 7 / 9
0.24.1 7 / 9
0.24.0 7 / 9
0.23.0 7 / 9
0.22.1 7 / 9
0.22.0 7 / 9
0.21.0 7 / 9
0.20.0 7 / 9
0.19.1 7 / 9
0.19.0 7 / 9
0.18.0 7 / 9
0.17.5 7 / 9
0.17.4 7 / 9
0.17.3 7 / 9
0.17.2 7 / 9
0.17.1 7 / 9
0.17.0 7 / 9
0.16.2 7 / 9
0.16.1 7 / 9
0.16.0 7 / 9
0.15.1 7 / 9
0.15.0 7 / 9
0.14.0 6 / 9
0.13.0 6 / 9
0.12.2 6 / 9
0.12.1 6 / 9
0.12.0 6 / 9
0.11.0 6 / 9
0.10.0 6 / 9
0.9.4 6 / 9
0.9.3 6 / 9
0.9.2 6 / 9
0.9.1 6 / 9
0.9.0 6 / 9
0.8.2 6 / 9
0.8.1 6 / 9
0.8.0 6 / 9
0.7.0 6 / 8
0.6.0 5 / 8
0.5.1 5 / 7
0.5.0 5 / 7
0.4.1 5 / 7
0.4.0 5 / 7
0.3.1 4 / 7
0.3.0 4 / 7
0.2.0 4 / 7
0.1.2 4 / 7
0.0.2 4 / 7
0.0.1 4 / 7

v0.40.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.39.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.39.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.38.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.35.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.34.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.