simple-keyboard
On-screen Javascript Virtual Keyboard
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA attestation; legitimate automation, not a takeover. | ai |
Versions (showing 51 of 819)
| Version | Deps | Published |
|---|---|---|
| 3.8.173 | 0 / 31 | |
| 3.8.172 | 0 / 31 | |
| 3.8.171 | 0 / 31 | |
| 3.8.170 | 0 / 31 | |
| 3.8.169 | 0 / 31 | |
| 3.8.168 | 0 / 31 | |
| 3.8.167 | 0 / 31 | |
| 3.8.166 | 0 / 31 | |
| 3.8.165 | 0 / 31 | |
| 3.8.164 | 0 / 31 | |
| 3.8.163 | 0 / 31 | |
| 3.8.162 | 0 / 31 | |
| 3.8.161 | 0 / 31 | |
| 3.8.160 | 0 / 31 | |
| 3.8.159 | 0 / 31 | |
| 3.8.158 | 0 / 31 | |
| 3.8.157 | 0 / 31 | |
| 3.8.156 | 0 / 31 | |
| 3.8.155 | 0 / 31 | |
| 3.8.154 | 0 / 31 | |
| 3.8.153 | 0 / 31 | |
| 3.8.152 | 0 / 31 | |
| 3.8.151 | 0 / 31 | |
| 3.8.150 | 0 / 31 | |
| 3.8.149 | 0 / 31 | |
| 3.8.148 | 0 / 31 | |
| 3.8.147 | 0 / 31 | |
| 3.8.146 | 0 / 31 | |
| 3.8.145 | 0 / 31 | |
| 3.8.144 | 0 / 31 | |
| 3.8.143 | 0 / 31 | |
| 3.8.142 | 0 / 31 | |
| 3.8.141 | 0 / 31 | |
| 3.8.140 | 0 / 31 | |
| 3.8.139 | 0 / 31 | |
| 3.8.138 | 0 / 31 | |
| 3.8.137 | 0 / 31 | |
| 3.8.136 | 0 / 31 | |
| 3.8.135 | 0 / 31 | |
| 3.8.134 | 0 / 31 | |
| 3.8.133 | 0 / 31 | |
| 3.8.132 | 0 / 31 | |
| 3.8.131 | 0 / 31 | |
| 3.8.130 | 0 / 31 | |
| 3.8.129 | 0 / 31 | |
| 3.8.128 | 0 / 31 | |
| 3.8.127 | 0 / 31 | |
| 3.8.126 | 0 / 31 | |
| 3.8.125 | 0 / 31 | |
| 3.8.124 | 0 / 31 | |
| 3.8.123 | 0 / 31 |
v3.8.173
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.172
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.171
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.170
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.169
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.168
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.167
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.166
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.165
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.164
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.163
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.162
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.161
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.160
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.159
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.158
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.157
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.156
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.