← Home

appium-ios-device

22
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

jlippsimurchiedangrahamkazucocoaumut.uzgurnick.mokhnach

Keywords

appium

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Appium org migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation — a legitimate and encouraged supply chain improvement, not a takeover. ai
publish-pattern dormant-publish AI (publish-pattern): Appium is a well-established org; dormancy followed by CI/CD-automated publishing with SLSA attestation is consistent with legitimate maintenance resumption. ai
provenance slsa-provenance AI (provenance): Package publishes via GitHub Actions CI/CD with SLSA provenance; this is the expected pattern for the appium org's automated release pipeline. ai
phantom-deps phantom-dep:source-map-support AI (phantom-deps): source-map-support is a declared runtime dep used in config/build output; phantom-dep detection is a false positive for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): The dynamic require resolves a hardcoded relative path to the package's own package.json for version metadata — not a true dynamic require vulnerability. Stable false positive for this package. ai

Versions (showing 22 of 22)

Version Deps Published
3.1.19 6 / 12
3.1.18 7 / 13
3.1.17 7 / 16
3.1.16 7 / 16
3.1.15 7 / 16
3.1.14 7 / 16
3.1.13 8 / 17
3.1.12 8 / 17
3.1.11 8 / 17
3.1.10 8 / 17
3.1.9 8 / 17
3.1.8 8 / 17
3.1.7 8 / 17
3.1.6 8 / 18
3.1.5 8 / 18
3.1.4 9 / 18
3.1.3 9 / 18
3.1.2 9 / 18
3.1.1 9 / 18
3.1.0 9 / 18
3.0.1 10 / 18
3.0.0 10 / 18

v3.1.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.