bun-query-builder
A simple yet performant query builder for TypeScript. Built with Bun.
Supply chain provenance
Status for the latest visible version.
This version carries a provenance attestation whose transparency-log entry uses a format our Sigstore verifier does not parse yet, so we could not check it either way. That is a known gap on our side, not a finding about this package — the npm CLI bundled with Node 22 LTS still emits this format by default. Until support lands, the attestation grants no trust: unverifiable is not verified.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@stacksjs/launchpad | AI (phantom-deps): Declared in dependencies but only referenced in config files; phantom-dep heuristic is accurate here. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with stacksjs org automation pattern. | ai | |
| provenance | no-provenance | AI (provenance): Established stacksjs publisher; lack of provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:@stacksjs/clapp | AI (phantom-deps): Config-file reference only; not a real import risk for this package. | ai | |
| phantom-deps | phantom-dep:dynamodb-tooling | AI (phantom-deps): Config-file reference only; not a real import risk for this package. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 0.1.62 | 4 / 1 | |
| 0.1.61 | 4 / 1 | |
| 0.1.60 | 4 / 1 | |
| 0.1.59 | 4 / 1 | |
| 0.1.58 | 4 / 1 | |
| 0.1.57 | 4 / 1 | |
| 0.1.56 | 4 / 1 | |
| 0.1.55 | 4 / 1 | |
| 0.1.54 | 4 / 1 | |
| 0.1.53 | 4 / 1 | |
| 0.1.52 | 4 / 1 | |
| 0.1.51 | 4 / 1 | |
| 0.1.50 | 4 / 1 | |
| 0.1.49 | 4 / 1 | |
| 0.1.48 | 4 / 1 | |
| 0.1.47 | 4 / 1 | |
| 0.1.46 | 4 / 1 | |
| 0.1.45 | 4 / 1 | |
| 0.1.44 | 4 / 1 | |
| 0.1.41 | 4 / 1 | |
| 0.1.40 | 4 / 1 | |
| 0.1.39 | 4 / 1 | |
| 0.1.38 | 4 / 1 | |
| 0.1.37 | 4 / 1 | |
| 0.1.36 | 4 / 1 | |
| 0.1.35 | 4 / 1 | |
| 0.1.34 | 4 / 1 | |
| 0.1.33 | 4 / 1 | |
| 0.1.32 | 4 / 1 | |
| 0.1.31 | 4 / 1 | |
| 0.1.30 | 4 / 1 | |
| 0.1.29 | 4 / 1 | |
| 0.1.28 | 4 / 1 | |
| 0.1.27 | 4 / 1 | |
| 0.1.26 | 4 / 1 | |
| 0.1.25 | 4 / 1 | |
| 0.1.24 | 4 / 1 | |
| 0.1.23 | 4 / 1 | |
| 0.1.21 | 4 / 1 | |
| 0.1.20 | 4 / 1 | |
| 0.1.18 | 4 / 1 | |
| 0.1.17 | 4 / 1 | |
| 0.1.13 | 4 / 1 | |
| 0.1.12 | 4 / 1 | |
| 0.1.11 | 4 / 1 | |
| 0.1.10 | 3 / 1 | |
| 0.1.9 | 3 / 1 | |
| 0.1.5 | 2 / 1 |
v0.1.62
1 findingThis version's attestation uses a transparency-log entry format (intoto/0.0.2) that our Sigstore verifier cannot parse, so its authenticity could not be established either way. This is a KNOWN GAP ON OUR SIDE, tracked as GitLab #229 — support for this entry type is planned, and the cryptography involved is entry-type-agnostic. It is not evidence of anything wrong with the package. It is also common and current rather than merely historical: the npm CLI bundled with Node 22 LTS still emits this format by default, so a routine CI publish lands here. Until #229 ships the attestation grants no trust — unsupported is not verified — but do not read it as a failed verification.
v0.1.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.58
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.57
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.