← Home

svix

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

tasnsvixdev

Keywords

svixdiahookwebhookstypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): OpenAPI codegen expansion, benign for this package. ai
source-diff large-new-source-files AI (source-diff): Generated OpenAPI client surface; expected for this SDK. ai
source-diff obfuscated-file:src/openapi/index.ts AI (source-diff): Auto-generated OpenAPI re-export barrel with long lines; not obfuscation. ai
phantom-deps phantom-dep:es6-promise AI (phantom-deps): Polyfill loaded by convention, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:url-parse AI (phantom-deps): url-parse is a declared runtime dep used via config/type references; stable false positive for this package. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Framework-scoped type package; not directly imported by convention. Stable false positive. ai
provenance publisher-changed AI (provenance): Migrated to GitHub Actions CI/CD publishing with SLSA provenance; legitimate automation change. ai
publish-pattern dormant-publish AI (publish-pattern): Established package with 371 versions; dormancy gap is normal for stable SDKs. ai

Versions (showing 51 of 97)

View all versions
Version Deps Published
1.99.1 1 / 4
1.99.0 1 / 4
1.98.0 1 / 4
1.97.0 1 / 4
1.96.1 1 / 4
1.96.0 1 / 4
1.95.2 1 / 4
1.95.1 1 / 4
1.95.0 1 / 4
1.94.0 1 / 4
1.93.0 1 / 4
1.92.2 1 / 4
1.91.1 2 / 5
1.91.0 2 / 5
1.90.0 2 / 5
1.89.0 2 / 5
1.88.0 2 / 5
1.87.0 2 / 5
1.86.0 2 / 5
1.85.0 2 / 6
1.84.1 2 / 6
1.82.0 3 / 6
1.81.0 3 / 6
1.80.0 3 / 6
1.79.0 3 / 6
1.78.0 3 / 6
1.77.0 3 / 6
1.76.1 6 / 13
1.76.0 6 / 13
1.75.1 6 / 13
1.75.0 6 / 13
1.74.1 6 / 13
1.74.0 6 / 13
1.73.0 6 / 13
1.72.0 6 / 13
1.71.0 7 / 13
1.70.1 7 / 13
1.70.0 7 / 13
1.69.0 7 / 13
1.68.0 7 / 13
1.67.0 6 / 12
1.66.0 6 / 12
1.65.0 6 / 12
1.64.1 6 / 12
1.64.0 6 / 12
1.63.1 6 / 12
1.63.0 6 / 12
1.62.0 6 / 12
1.61.4 6 / 12
1.61.3 6 / 12
1.61.2 6 / 12

v1.99.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.99.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.98.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.97.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.64.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.64.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.63.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.63.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.62.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.61.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.61.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.61.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.