← Home

phonic

[![fern shield](https://img.shields.io/badge/%F0%9F%8C%BF-Built%20with%20Fern-brightgreen)](https://buildwithfern.com?utm_source=github&utm_medium=github&utm_campaign=readme&utm_source=https%3A%2F%2Fgithub.com%2FPhonic-Co%2Fphonic-node) [![npm shield](htt

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

moroshkomoinnadeemnikhil.murthyqiongzhouhelizabethz

Versions (showing 51 of 85)

View all versions
Version Deps Published
0.32.11 1 / 12
0.32.10 1 / 12
0.32.2 1 / 12
0.32.1 1 / 12
0.32.0 1 / 12
0.31.15 1 / 12
0.31.13 1 / 12
0.31.12 1 / 12
0.31.11 1 / 12
0.31.10 1 / 12
0.31.2 1 / 12
0.31.1 1 / 12
0.31.0 1 / 12
0.30.40 1 / 12
0.30.33 1 / 12
0.30.31 1 / 12
0.30.23 1 / 12
0.30.22 1 / 12
0.30.21 1 / 12
0.30.20 1 / 12
0.30.19 1 / 12
0.30.18 1 / 12
0.30.17 1 / 12
0.30.16 1 / 12
0.30.15 1 / 12
0.29.3 1 / 8
0.29.2 1 / 8
0.29.1 1 / 8
0.29.0 1 / 8
0.28.1 1 / 8
0.28.0 1 / 8
0.27.0 1 / 8
0.26.1 1 / 8
0.26.0 1 / 8
0.25.4 1 / 8
0.25.3 1 / 8
0.25.2 1 / 8
0.25.1 1 / 8
0.25.0 1 / 8
0.24.2 1 / 8
0.24.1 1 / 8
0.24.0 1 / 8
0.23.0 1 / 8
0.22.0 1 / 8
0.21.1 1 / 8
0.21.0 1 / 8
0.20.0 1 / 8
0.19.1 1 / 8
0.19.0 1 / 8
0.18.6 1 / 8
0.18.5 1 / 8

v0.32.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.32.10

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: qiongzhouh → GitHub Actions (on 2026-07-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (qiongzhouh) on 2026-07-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.