← Home

svgtofont

14
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

wcjiang

Keywords

webfontfonticoniconfontfont-facecompressminifyfont-clittfwoffeotsvgttf2eotttf2woffttf2svgsvg2ttfcssbase64

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance slsa-provenance AI (provenance): Package consistently published via GitHub Actions CI with SLSA attestation; this is the expected publisher pattern. ai
provenance publisher-changed AI (provenance): Transition from wcjiang to GitHub Actions reflects CI/CD automation by the same maintainer org, corroborated by SLSA attestation. ai
publish-pattern dormant-publish AI (publish-pattern): Long-lived package with 127 versions; dormancy followed by CI-attested publish is consistent with resumed maintenance, not takeover. ai
dependencies unvetted-dep:image2uri AI (dependencies): image2uri is a legitimate utility for SVG/font tooling; stable use across versions of this package. ai

Versions (showing 14 of 14)

Version Deps Published
6.5.3 13 / 6
6.5.2 13 / 6
6.5.1 13 / 6
6.5.0 13 / 6
6.4.1 13 / 6
6.4.0 13 / 6
6.3.2 13 / 6
6.3.1 13 / 6
6.3.0 13 / 6
6.2.0 13 / 6
6.1.1 13 / 6
6.1.0 13 / 6
6.0.1 13 / 6
6.0.0 13 / 6

v6.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.