vhd-lib
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): elise-f is an established publisher (43 approved packages) within the Vates org; transition appears legitimate. | ai | |
| provenance | publisher-changed | AI (provenance): elise-f is a Vates SAS team member with 43 approved packages; consistent with org-internal maintainer rotation. | ai | |
| dependencies | unvetted-dep:@vates/read-chunk | AI (dependencies): First-party @vates org dep from same xen-orchestra monorepo. | ai | |
| dependencies | unvetted-dep:@xen-orchestra/fs | AI (dependencies): First-party @xen-orchestra org dep from same monorepo. | ai | |
| dependencies | unvetted-dep:@xen-orchestra/log | AI (dependencies): First-party @xen-orchestra org dep from same monorepo. | ai | |
| dependencies | unvetted-dep:struct-fu | AI (dependencies): Stable third-party dep used by this package across many versions. | ai | |
| dependencies | unvetted-dep:async-iterator-to-stream | AI (dependencies): Stable utility dep used by this package across many versions. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): fs-extra is declared in dependencies; phantom-dep heuristic false positive. | ai | |
| dependencies | unvetted-dep:@vates/stream-reader | AI (dependencies): First-party @vates org dep from same xen-orchestra monorepo. | ai | |
| dependencies | unvetted-dep:@vates/diff | AI (dependencies): First-party @vates org dep from same xen-orchestra monorepo. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 4.16.1 | 16 / 6 | |
| 4.16.0 | 16 / 6 | |
| 4.15.0 | 16 / 6 | |
| 4.14.7 | 16 / 5 | |
| 4.14.6 | 16 / 5 | |
| 4.14.5 | 16 / 5 | |
| 4.14.4 | 16 / 5 | |
| 4.14.3 | 16 / 5 | |
| 4.14.2 | 16 / 5 | |
| 4.14.1 | 16 / 5 | |
| 4.14.0 | 16 / 5 | |
| 4.13.0 | 16 / 5 | |
| 4.12.0 | 16 / 5 |
v4.16.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mathieura) than the most recent previously approved version (b-nollet) on 2026-07-27, but mathieura is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.