← Home

contentful

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

contentful-ecosystem

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:contentful-resolve-response AI (dependencies): contentful-resolve-response is a first-party Contentful package; stable dependency across versions. ai

Versions (showing 100 of 107)

Version Deps Published
11.12.7 8 / 34
11.12.6 8 / 34
11.12.5 8 / 34
11.12.4 8 / 34
11.12.3 8 / 34
11.12.2 8 / 34
11.12.1 8 / 34
11.12.0 8 / 34
11.11.1 8 / 34
11.11.0 8 / 34
11.10.7 8 / 34
11.10.6 8 / 34
11.10.5 8 / 34
11.10.4 8 / 34
11.10.3 8 / 34
11.10.2 8 / 33
11.10.1 8 / 33
11.10.0 7 / 33
11.9.0 7 / 33
11.8.13 7 / 33
11.8.12 7 / 33
11.8.11 7 / 33
11.8.10 7 / 33
11.8.9 7 / 33
11.8.8 7 / 33
11.8.7 7 / 33
11.8.6 7 / 33
11.8.5 7 / 33
11.8.4 7 / 33
11.8.3 7 / 33
11.8.2 7 / 33
11.8.1 7 / 33
11.8.0 7 / 33
11.7.19 7 / 33
11.7.18 7 / 33
11.7.17 7 / 33
11.7.16 7 / 33
11.7.15 7 / 33
11.7.14 7 / 33
11.7.13 7 / 33
11.7.12 7 / 33
11.7.11 7 / 33
11.7.10 7 / 33
11.7.9 7 / 33
11.7.8 7 / 33
11.7.7 7 / 33
11.7.6 7 / 33
11.7.5 7 / 33
11.7.4 7 / 33
11.7.3 7 / 33
11.7.2 7 / 33
11.7.1 7 / 33
11.7.0 7 / 33
11.6.0 7 / 33
11.5.25 7 / 33
11.5.24 7 / 33
11.5.23 7 / 33
11.5.22 7 / 33
11.5.21 7 / 33
11.5.20 7 / 33
11.5.19 7 / 33
11.5.18 7 / 33
11.5.17 7 / 33
11.5.16 7 / 33
11.5.15 7 / 33
11.5.14 7 / 33
11.5.13 7 / 33
11.5.12 7 / 33
11.5.11 7 / 33
11.5.10 7 / 33
11.5.9 7 / 33
11.5.8 7 / 33
11.5.7 7 / 33
11.5.6 7 / 33
11.5.5 7 / 33
11.5.4 7 / 33
11.5.3 7 / 33
11.5.2 7 / 33
11.5.1 7 / 33
11.5.0 7 / 33
11.4.6 7 / 33
11.4.5 7 / 33
11.4.4 7 / 39
11.4.3 7 / 39
11.4.2 7 / 39
11.4.1 7 / 39
11.4.0 7 / 39
11.3.4 7 / 39
11.3.3 7 / 39
11.3.2 7 / 39
11.3.1 7 / 39
11.3.0 7 / 39
11.2.6 7 / 39
11.2.5 7 / 39
11.2.4 7 / 39
11.2.3 7 / 39
11.2.2 7 / 39
11.2.1 7 / 39
11.2.0 7 / 38
11.1.4 7 / 38
Showing 100 of 107 Next page →

v11.12.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.