oci-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): 169.254.169.254 is the standard cloud instance metadata service endpoint; expected and documented for OCI SDK. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decoding a token/JWT response body from the metadata service; legitimate SDK behavior. | ai | |
| phantom-deps | phantom-dep:@types/uuid | AI (phantom-deps): @types/* packages are type-only; stable false positive for TypeScript SDKs. | ai | |
| phantom-deps | phantom-dep:@types/sshpk | AI (phantom-deps): @types/* packages are type-only; stable false positive for TypeScript SDKs. | ai | |
| phantom-deps | phantom-dep:@types/opossum | AI (phantom-deps): @types/* packages are type-only; stable false positive for TypeScript SDKs. | ai | |
| phantom-deps | phantom-dep:@types/jsonwebtoken | AI (phantom-deps): @types/* packages are type-only; stable false positive for TypeScript SDKs. | ai | |
| phantom-deps | phantom-dep:@types/isomorphic-fetch | AI (phantom-deps): @types/* packages are type-only; stable false positive for TypeScript SDKs. | ai |
Versions (showing 51 of 99)
| Version | Deps | Published |
|---|---|---|
| 2.137.1 | 13 / 14 | |
| 2.137.0 | 13 / 14 | |
| 2.136.1 | 13 / 14 | |
| 2.136.0 | 13 / 14 | |
| 2.135.1 | 13 / 14 | |
| 2.135.0 | 13 / 14 | |
| 2.134.1 | 13 / 14 | |
| 2.132.0 | 13 / 14 | |
| 2.131.2 | 13 / 14 | |
| 2.131.1 | 13 / 14 | |
| 2.131.0 | 13 / 14 | |
| 2.130.0 | 13 / 14 | |
| 2.129.0 | 13 / 14 | |
| 2.127.0 | 13 / 14 | |
| 2.126.3 | 13 / 14 | |
| 2.126.2 | 13 / 14 | |
| 2.126.1 | 13 / 13 | |
| 2.126.0 | 13 / 13 | |
| 2.125.3 | 13 / 13 | |
| 2.125.2 | 13 / 13 | |
| 2.125.1 | 13 / 13 | |
| 2.125.0 | 13 / 13 | |
| 2.124.0 | 13 / 13 | |
| 2.123.1 | 13 / 13 | |
| 2.123.0 | 13 / 13 | |
| 2.122.2 | 13 / 13 | |
| 2.122.1 | 13 / 13 | |
| 2.122.0 | 13 / 13 | |
| 2.121.1 | 13 / 13 | |
| 2.121.0 | 13 / 13 | |
| 2.120.0 | 13 / 13 | |
| 2.119.1 | 13 / 13 | |
| 2.119.0 | 13 / 13 | |
| 2.118.1 | 13 / 13 | |
| 2.118.0 | 13 / 13 | |
| 2.117.1 | 13 / 13 | |
| 2.117.0 | 13 / 13 | |
| 2.116.2 | 13 / 13 | |
| 2.116.1 | 13 / 13 | |
| 2.116.0 | 13 / 13 | |
| 2.115.0 | 13 / 13 | |
| 2.114.1 | 13 / 13 | |
| 2.114.0 | 13 / 13 | |
| 2.113.0 | 13 / 13 | |
| 2.112.2 | 13 / 13 | |
| 2.112.1 | 13 / 13 | |
| 2.112.0 | 13 / 13 | |
| 2.111.3 | 13 / 13 | |
| 2.111.2 | 13 / 13 | |
| 2.111.1 | 13 / 13 | |
| 2.111.0 | 13 / 13 |
v2.137.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.137.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.136.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.136.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.