← Home

nuxtseo-shared

46
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

harlan_zw

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Legitimate migration from personal npm account to GitHub Actions CI/CD publishing with SLSA provenance. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Config-file reference; stable pattern for this build-tool package. ai
phantom-deps phantom-dep:consola AI (phantom-deps): Config-file reference; stable pattern for this build-tool package. ai
phantom-deps phantom-dep:pkg-types AI (phantom-deps): Config-file reference; stable pattern for this build-tool package. ai
phantom-deps phantom-dep:@clack/prompts AI (phantom-deps): Config-file reference; stable pattern for this build-tool package. ai

Versions (showing 46 of 46)

Version Deps Published
5.3.6 14 / 12
5.3.4 14 / 12
5.3.3 14 / 11
5.3.2 14 / 11
5.3.1 14 / 11
5.3.0 14 / 11
5.2.6 13 / 11
5.2.5 13 / 11
5.2.4 13 / 11
5.2.3 13 / 11
5.2.2 13 / 11
5.2.1 13 / 11
5.2.0 13 / 11
5.1.4 13 / 11
5.1.3 13 / 9
5.1.2 13 / 9
5.1.1 13 / 9
5.1.0 13 / 8
5.0.2 13 / 8
5.0.1 13 / 8
0.9.0 13 / 8
0.8.3 13 / 8
0.8.2 13 / 8
0.8.1 13 / 8
0.8.0 13 / 8
0.7.1 13 / 8
0.7.0 13 / 8
0.6.1 13 / 8
0.6.0 13 / 8
0.5.3 12 / 8
0.5.2 12 / 8
0.5.1 12 / 8
0.5.0 12 / 8
0.4.0 12 / 8
0.3.0 12 / 8
0.2.0 12 / 8
0.1.9 11 / 10
0.1.8 11 / 10
0.1.7 11 / 10
0.1.6 11 / 10
0.1.5 11 / 10
0.1.4 11 / 10
0.1.3 11 / 10
0.1.2 11 / 10
0.1.1 11 / 12
0.1.0 11 / 12

v5.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.