← Home

unstorage

Universal Storage Layer

27
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

pi0

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:mkdir AI (dependencies): Tiny well-known utility package, no risk indicators. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Optional driver dependency, config-referenced not a risk. ai
phantom-deps phantom-dep:mri AI (phantom-deps): CLI helper dep, used indirectly via build config. ai
phantom-deps phantom-dep:mkdir AI (phantom-deps): Small utility dep used in driver code paths. ai
phantom-deps phantom-dep:listhen AI (phantom-deps): Used in server/dev tooling, config-referenced. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding in azure-key-vault driver is standard Azure Key Vault integration code for decoding secret values; not a malicious payload. ai
dependencies unvetted-dep:h3 AI (dependencies): h3 is a well-known unjs HTTP framework maintained by the same author (pi0); legitimate ecosystem dependency. ai
dependencies unvetted-dep:destr AI (dependencies): destr is a well-known unjs safe JSON deserializer maintained by the same author (pi0); legitimate ecosystem dependency. ai
dependencies unvetted-dep:ofetch AI (dependencies): ofetch is a well-known unjs fetch wrapper maintained by the same author (pi0); legitimate ecosystem dependency. ai
dependencies unvetted-dep:node-fetch-native AI (dependencies): node-fetch-native is a well-known unjs package maintained by the same author (pi0); legitimate ecosystem dependency. ai

Versions (showing 27 of 27)

Version Deps Published
1.17.5 8 / 51
1.17.4 8 / 51
1.17.3 8 / 51
1.17.2 8 / 51
1.17.1 8 / 51
1.17.0 8 / 51
1.16.1 8 / 50
1.16.0 8 / 50
1.15.0 8 / 50
1.14.4 8 / 50
1.14.3 8 / 50
1.14.2 8 / 50
1.14.1 10 / 48
1.14.0 10 / 48
1.13.1 10 / 40
1.13.0 10 / 40
1.12.0 10 / 40
1.11.1 10 / 40
1.11.0 10 / 40
1.6.0 11 / 36
1.5.0 11 / 34
1.4.1 11 / 34
1.4.0 18 / 34
1.3.0 18 / 34
1.2.0 18 / 34
1.0.1 11 / 23
1.0.0 11 / 23

v1.6.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: pi0.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.