← Home

bun-query-builder

A simple yet performant query builder for TypeScript. Built with Bun.

48
Versions
MIT
License
No
Install Scripts
Unverifiable
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (format we cannot verify yet) npm registry signatures No source commit

This version carries a provenance attestation whose transparency-log entry uses a format our Sigstore verifier does not parse yet, so we could not check it either way. That is a known gap on our side, not a finding about this package — the npm CLI bundled with Node 22 LTS still emits this format by default. Until support lands, the attestation grants no trust: unverifiable is not verified.

Maintainers

chrisbreuer

Keywords

typescriptquery-builderbunpackage

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@stacksjs/launchpad AI (phantom-deps): Declared in dependencies but only referenced in config files; phantom-dep heuristic is accurate here. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with stacksjs org automation pattern. ai
provenance no-provenance AI (provenance): Established stacksjs publisher; lack of provenance is common and not a risk signal here. ai
phantom-deps phantom-dep:@stacksjs/clapp AI (phantom-deps): Config-file reference only; not a real import risk for this package. ai
phantom-deps phantom-dep:dynamodb-tooling AI (phantom-deps): Config-file reference only; not a real import risk for this package. ai

Versions (showing 48 of 48)

Version Deps Published
0.1.62 4 / 1
0.1.61 4 / 1
0.1.60 4 / 1
0.1.59 4 / 1
0.1.58 4 / 1
0.1.57 4 / 1
0.1.56 4 / 1
0.1.55 4 / 1
0.1.54 4 / 1
0.1.53 4 / 1
0.1.52 4 / 1
0.1.51 4 / 1
0.1.50 4 / 1
0.1.49 4 / 1
0.1.48 4 / 1
0.1.47 4 / 1
0.1.46 4 / 1
0.1.45 4 / 1
0.1.44 4 / 1
0.1.41 4 / 1
0.1.40 4 / 1
0.1.39 4 / 1
0.1.38 4 / 1
0.1.37 4 / 1
0.1.36 4 / 1
0.1.35 4 / 1
0.1.34 4 / 1
0.1.33 4 / 1
0.1.32 4 / 1
0.1.31 4 / 1
0.1.30 4 / 1
0.1.29 4 / 1
0.1.28 4 / 1
0.1.27 4 / 1
0.1.26 4 / 1
0.1.25 4 / 1
0.1.24 4 / 1
0.1.23 4 / 1
0.1.21 4 / 1
0.1.20 4 / 1
0.1.18 4 / 1
0.1.17 4 / 1
0.1.13 4 / 1
0.1.12 4 / 1
0.1.11 4 / 1
0.1.10 3 / 1
0.1.9 3 / 1
0.1.5 2 / 1

v0.1.62

1 finding
MEDIUM Provenance attestation is in an unverifiable format provenance

This version's attestation uses a transparency-log entry format (intoto/0.0.2) that our Sigstore verifier cannot parse, so its authenticity could not be established either way. This is a KNOWN GAP ON OUR SIDE, tracked as GitLab #229 — support for this entry type is planned, and the cryptography involved is entry-type-agnostic. It is not evidence of anything wrong with the package. It is also common and current rather than merely historical: the npm CLI bundled with Node 22 LTS still emits this format by default, so a routine CI publish lands here. Until #229 ships the attestation grants no trust — unsupported is not verified — but do not read it as a failed verification.

v0.1.61

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.60

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.59

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.58

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.57

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.56

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.52

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.50

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.