← Home

rete

1
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ni55an

Keywords

dataflowvisual programmingnode editorreteRete.js

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:vite AI (typosquat): 'rete' is the package's own brand name (Rete.js framework), not a typosquat of vite. ai
install-scripts install-script:postinstall AI (install-scripts): Established framework with SLSA provenance; postinstall is a benign compatibility/setup script. ai

Versions (showing 1 of 1)

Version Deps Published
2.0.6 1 / 0

v2.0.6

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.js

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.