← Home

polylabel

3
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mapbox-npm-01mapbox-npm-02mapbox-npm-07mapbox-npm-03mapbox-npm-04mapbox-npm-09mapbox-npm-05mapbox-npm-06mapbox-npm-08mapbox-npm-advanced-actionsmapbox-npm-cimapbox-npmmapbox-adminmapbox-machine-usermbx-npm-ci-stagingmbx-npm-ci-productionmbx-npm-01-productionmbx-npm-02-productionmbx-npm-03-productionmbx-npm-04-productionmbx-npm-05-productionmbx-npm-06-productionmbx-npm-07-productionmbx-npm-08-productionmbx-npm-09-productionmbx-npm-02-stagingmbx-npm-advanced-actions-stagingmbx-npm-advanced-actions-productionmourner

Keywords

polygongeometryalgorithm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from mourner to GitHub Actions CI/CD; provenance improved with SLSA attestation. ai
publish-pattern dormant-publish AI (publish-pattern): Mature, stable library; infrequent publishes are normal for this package. ai
provenance no-provenance AI (provenance): Established Mapbox/mourner package with long history; lack of Sigstore provenance is not a meaningful risk signal here. ai

Versions (showing 3 of 3)

Version Deps Published
2.1.0 1 / 2
2.0.1 1 / 2
2.0.0 1 / 2

v2.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.