← Home

versions

CLI to increment a project's version and optionally publish release to Github/Gitea

26
Versions
BSD-2-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

silverwind

Keywords

versionsemverbumpreleasecligitgithubgiteachangelog

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA/Sigstore attestation present; gitHead absence is benign when full provenance attestation exists. ai
publish-pattern dormant-publish AI (publish-pattern): Established 105-version package with consistent authorship; dormancy followed by CI-attested publish is low risk. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI with SLSA attestation; stable signal for this package. ai

Versions (showing 26 of 26)

Version Deps Published
15.1.4 0 / 14
15.1.3 0 / 14
15.1.2 0 / 14
15.1.1 0 / 14
15.1.0 0 / 14
15.0.4 0 / 14
15.0.3 0 / 14
15.0.2 0 / 14
15.0.1 0 / 14
15.0.0 0 / 14
14.3.2 0 / 14
14.3.1 0 / 13
14.3.0 0 / 13
14.2.7 0 / 13
14.2.6 0 / 13
14.2.5 0 / 15
14.2.4 0 / 15
14.2.2 0 / 15
14.2.1 0 / 15
14.2.0 0 / 15
14.1.3 0 / 15
14.1.2 0 / 14
14.1.1 0 / 13
14.1.0 0 / 13
14.0.4 0 / 13
14.0.3 0 / 12

v15.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.