← Home

contentful

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

contentful-ecosystem

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:contentful-resolve-response AI (dependencies): contentful-resolve-response is a first-party Contentful package; stable dependency across versions. ai

Versions (showing 51 of 107)

View all versions
Version Deps Published
11.12.7 8 / 34
11.12.6 8 / 34
11.12.5 8 / 34
11.12.4 8 / 34
11.12.3 8 / 34
11.12.2 8 / 34
11.12.1 8 / 34
11.12.0 8 / 34
11.11.1 8 / 34
11.11.0 8 / 34
11.10.7 8 / 34
11.10.6 8 / 34
11.10.5 8 / 34
11.10.4 8 / 34
11.10.3 8 / 34
11.10.2 8 / 33
11.10.1 8 / 33
11.10.0 7 / 33
11.9.0 7 / 33
11.8.13 7 / 33
11.8.12 7 / 33
11.8.11 7 / 33
11.8.10 7 / 33
11.8.9 7 / 33
11.8.8 7 / 33
11.8.7 7 / 33
11.8.6 7 / 33
11.8.5 7 / 33
11.8.4 7 / 33
11.8.3 7 / 33
11.8.2 7 / 33
11.8.1 7 / 33
11.8.0 7 / 33
11.7.19 7 / 33
11.7.18 7 / 33
11.7.17 7 / 33
11.7.16 7 / 33
11.7.15 7 / 33
11.7.14 7 / 33
11.7.13 7 / 33
11.7.12 7 / 33
11.7.11 7 / 33
11.7.10 7 / 33
11.7.9 7 / 33
11.7.8 7 / 33
11.7.7 7 / 33
11.7.6 7 / 33
11.7.5 7 / 33
11.7.4 7 / 33
11.7.3 7 / 33
11.7.2 7 / 33

v11.12.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.