← Home

updates

CLI dependency update tool for npm, uv, cargo, go and actions

90
Versions
BSD-2-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

silverwind

Keywords

clidependenciesupdateupgradeoutdatedversionsncunpmuvcargogolangrustpythongithub-actionsdockermakefile

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation provides stronger supply chain integrity than gitHead; acceptable for this well-established package. ai
source-diff obfuscated-file:dist/rc-DlHsBps6.js AI (source-diff): Minified bundle in dist/ is expected build output for this package; content is readable rc/ini parsing logic. ai
source-diff obfuscated-file:dist/shared.js AI (source-diff): dist/ is the tsdown build output; minified ESM bundles are expected and stable for this package. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms legitimate CI publish; dormancy flag is a false positive here. ai

Versions (showing 90 of 90)

Version Deps Published
17.19.2 0 / 15
17.19.1 0 / 15
17.19.0 0 / 15
17.18.2 0 / 15
17.18.1 0 / 15
17.18.0 0 / 15
17.17.3 0 / 15
17.17.2 0 / 15
17.17.1 0 / 15
17.17.0 0 / 15
17.16.13 0 / 15
17.16.12 0 / 15
17.16.11 0 / 15
17.16.10 0 / 15
17.16.9 0 / 15
17.16.8 0 / 15
17.16.7 0 / 15
17.16.6 0 / 15
17.16.5 0 / 15
17.16.4 0 / 15
17.16.3 0 / 15
17.16.2 0 / 15
17.16.1 0 / 15
17.16.0 0 / 15
17.15.7 0 / 15
17.15.6 0 / 15
17.15.5 0 / 15
17.15.4 0 / 15
17.15.3 0 / 15
17.15.2 0 / 15
17.15.0 0 / 15
17.14.2 0 / 14
17.14.1 0 / 14
17.14.0 0 / 14
17.13.5 0 / 14
17.13.4 0 / 14
17.13.3 0 / 14
17.13.2 0 / 13
17.13.1 0 / 13
17.13.0 0 / 13
17.12.0 0 / 13
17.11.7 0 / 13
17.11.6 0 / 13
17.11.5 0 / 13
17.11.4 0 / 14
17.11.3 0 / 14
17.11.2 0 / 14
17.11.1 0 / 14
17.11.0 0 / 14
17.10.1 0 / 14
17.10.0 0 / 14
17.9.1 0 / 14
17.9.0 0 / 14
17.8.3 0 / 14
17.8.2 0 / 14
17.8.1 0 / 14
17.8.0 0 / 15
17.7.0 0 / 15
17.6.2 0 / 15
17.6.1 0 / 15
17.6.0 0 / 16
17.5.11 0 / 16
17.5.10 0 / 16
17.5.9 0 / 16
17.5.8 0 / 16
17.5.7 0 / 16
17.5.6 0 / 16
17.5.5 0 / 16
17.5.4 0 / 16
17.5.3 0 / 18
17.5.2 0 / 18
17.5.1 0 / 17
17.5.0 0 / 17
17.4.0 0 / 17
17.3.2 0 / 17
17.3.1 0 / 17
17.3.0 0 / 17
17.2.0 0 / 20
17.1.0 0 / 20
17.0.9 0 / 20
17.0.8 0 / 21
17.0.7 0 / 21
17.0.6 0 / 21
17.0.5 0 / 21
17.0.4 0 / 21
17.0.3 0 / 21
17.0.2 0 / 20
17.0.1 0 / 20
17.0.0 0 / 20
16.9.2 0 / 20

v17.19.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.19.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.18.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.18.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.