← Home

datastore-core

7
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

achingbrainnpm-service-account-ipfs

Keywords

datastoreinterfaceipfskey-value

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:it-pipe AI (dependencies): it-pipe is a standard async-iterable utility from the IPFS/libp2p ecosystem; its use in datastore-core is expected and appropriate. ai
dependencies unvetted-dep:it-sort AI (dependencies): it-sort is a standard async-iterable utility from the IPFS/libp2p ecosystem; its use in datastore-core is expected and appropriate. ai
dependencies unvetted-dep:it-take AI (dependencies): it-take is a standard async-iterable utility from the IPFS/libp2p ecosystem; its use in datastore-core is expected and appropriate. ai
dependencies unvetted-dep:it-drain AI (dependencies): it-drain is a standard async-iterable utility from the IPFS/libp2p ecosystem; its use in datastore-core is expected and appropriate. ai
dependencies unvetted-dep:it-merge AI (dependencies): it-merge is a standard async-iterable utility from the IPFS/libp2p ecosystem; its use in datastore-core is expected and appropriate. ai
dependencies unvetted-dep:it-filter AI (dependencies): it-filter is a standard async-iterable utility from the IPFS/libp2p ecosystem; its use in datastore-core is expected and appropriate. ai

Versions (showing 7 of 7)

Version Deps Published
12.0.1 11 / 4
12.0.0 11 / 4
11.0.4 10 / 4
11.0.3 10 / 4
11.0.2 10 / 4
11.0.1 10 / 4
11.0.0 10 / 4

v12.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.