ts-proto
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:ts-poet | AI (dependencies): ts-poet is a legitimate TypeScript code generation library and a long-standing core dependency of ts-proto; stable across versions. | ai | |
| dependencies | unvetted-dep:case-anything | AI (dependencies): case-anything is a well-known string case transformation utility; legitimate and expected dependency for ts-proto. | ai | |
| dependencies | unvetted-dep:ts-proto-descriptors | AI (dependencies): ts-proto-descriptors is the companion protobuf descriptor package for ts-proto; a stable, expected dependency maintained by the same project. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 2.11.8 | 4 / 40 | |
| 2.11.7 | 4 / 40 | |
| 2.11.6 | 4 / 40 | |
| 2.11.5 | 4 / 40 | |
| 2.11.4 | 4 / 40 | |
| 2.11.2 | 4 / 40 | |
| 2.11.1 | 4 / 40 | |
| 2.11.0 | 4 / 40 | |
| 2.10.1 | 4 / 40 | |
| 2.10.0 | 4 / 40 | |
| 2.9.0 | 4 / 40 | |
| 2.8.3 | 4 / 39 | |
| 2.8.2 | 4 / 39 | |
| 2.8.1 | 4 / 39 | |
| 2.8.0 | 4 / 39 | |
| 2.7.7 | 4 / 37 | |
| 2.7.6 | 4 / 37 | |
| 2.7.5 | 4 / 37 | |
| 2.7.4 | 4 / 37 | |
| 2.7.3 | 4 / 37 | |
| 2.7.2 | 4 / 37 | |
| 2.7.1 | 4 / 37 |
v2.11.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.8.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.7.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.7.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.7.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.