← Home

ulidx

8
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

perrymitchell

Keywords

uliduuididgeneratorguid

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Runs simple-git-hooks dev-hook installer, no remote code; stable for this package. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): ulidx is a legitimate ULID library; name similarity to uuid is intentional (ULID is a UUID alternative), not a typosquat. ai

Versions (showing 8 of 8)

Version Deps Published
2.4.1 1 / 19
2.4.0 1 / 19
2.3.0 1 / 19
2.2.1 1 / 19
2.2.0 1 / 19
2.1.0 1 / 19
2.0.0 1 / 19
0.5.0 1 / 11

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: simple-git-hooks

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.