← Home

@zondax/zemu

Zemu Testing Framework

31
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jleniemmanuel-zondax

Keywords

ZondaxLedgerTestingZemu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:elfy AI (dependencies): elfy is a stable ELF-parsing library; its use is appropriate for a Ledger device testing framework. ai
phantom-deps phantom-dep:@ledgerhq/errors AI (phantom-deps): @ledgerhq/errors is a declared runtime dep; likely re-exported or used indirectly in this Ledger testing framework. ai

Versions (showing 31 of 31)

Version Deps Published
0.67.4 12 / 13
0.67.3 12 / 13
0.67.2 12 / 13
0.64.1 12 / 13
0.64.0 12 / 13
0.63.1 12 / 13
0.63.0 12 / 13
0.62.2 12 / 13
0.62.1 12 / 13
0.62.0 12 / 13
0.61.11 12 / 13
0.61.10 12 / 13
0.61.4 12 / 13
0.61.3 12 / 13
0.61.2 12 / 13
0.61.1 12 / 13
0.61.0 11 / 13
0.60.0 11 / 13
0.55.3 11 / 23
0.55.2 11 / 23
0.55.1 11 / 23
0.55.0 11 / 23
0.54.0 11 / 23
0.53.0 11 / 23
0.52.0 11 / 23
0.51.0 11 / 23
0.50.3 11 / 23
0.50.2 11 / 23
0.50.1 11 / 23
0.50.0 11 / 23
0.49.0 11 / 23

v0.55.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.55.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.55.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.55.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.54.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.53.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.52.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.51.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.