typia
Superfast runtime validators with only one line
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Package publishes via CI/CD with SLSA attestation; gitHead absence is benign for this build flow. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): tinyglobby is a legit glob utility added in a major refactor; benign. | ai | |
| source-diff | large-new-source-files | AI (source-diff): v13 native Go programmers; expected for this build-heavy package. | ai | |
| dependencies | unvetted-dep:@samchon/openapi | AI (dependencies): @samchon/openapi is the same author's (Jeongho Nam / samchon org) companion package; not a suspicious third-party dependency. Stable accept for this package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): typia ships a CLI tool that legitimately uses child_process for setup commands (CommandExecutor). This is expected behavior for a CLI utility, not malicious code execution. | ai | |
| phantom-deps | phantom-dep:@typia/core | AI (phantom-deps): @typia/core is a first-party monorepo package used as a configuration/peer dependency; not being directly imported in source is expected. | ai | |
| dependencies | unvetted-dep:@typia/transform | AI (dependencies): @typia/transform is a first-party sub-package in the typia monorepo (samchon/typia); not a third-party unknown dependency. | ai | |
| dependencies | unvetted-dep:@typia/core | AI (dependencies): @typia/core is a first-party sub-package in the typia monorepo (samchon/typia); not a third-party unknown dependency. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 13.2.0 | 7 / 8 | |
| 13.1.19 | 7 / 8 | |
| 13.1.1 | 7 / 8 | |
| 13.1.0 | 7 / 8 | |
| 13.0.2 | 7 / 8 | |
| 13.0.1 | 7 / 8 | |
| 13.0.0 | 7 / 12 | |
| 12.1.1 | 10 / 18 | |
| 12.1.0 | 10 / 18 | |
| 12.0.2 | 10 / 18 | |
| 12.0.1 | 10 / 18 | |
| 12.0.0 | 10 / 18 | |
| 11.0.3 | 7 / 21 | |
| 11.0.2 | 7 / 21 | |
| 11.0.1 | 7 / 21 | |
| 11.0.0 | 7 / 21 | |
| 10.1.0 | 7 / 21 | |
| 10.0.2 | 7 / 21 | |
| 10.0.1 | 7 / 21 | |
| 10.0.0 | 7 / 21 |
v13.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.0.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.0.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.1.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.