← Home

@actions/io

Actions io lib

11
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

chrispatbryanmacfarlanethboopkonradpabjancschleidenbdehamerjoshmgross

Keywords

githubactionsio

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): GitHub Actions toolkit moved to automated CI/CD publishing with SLSA provenance, which supersedes gitHead as a supply chain signal. ai
provenance publisher-changed AI (provenance): Legitimate transition from individual (jclem) to GitHub Actions org bot account for automated publishing of the official toolkit. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are known GitHub Actions team members; normal team rotation for the official actions/toolkit package. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers are former GitHub employees; normal team turnover for the official actions/toolkit package. ai
semgrep semgrep:child-process-import AI (semgrep): @actions/io is an official GitHub Actions I/O utility that legitimately uses child_process to invoke system tools (cp, mv, which, etc.). This is expected and documented behavior. ai
typosquat typosquat.levenshtein:zod AI (typosquat): @actions/io is GitHub's official scoped toolkit package; Levenshtein comparison to 'zod' is a stable false positive. ai
typosquat typosquat.levenshtein:koa AI (typosquat): @actions/io is GitHub's official scoped toolkit package; Levenshtein comparison to short unscoped names like 'koa' is a stable false positive for this package. ai
typosquat typosquat.levenshtein:pino AI (typosquat): @actions/io is GitHub's official scoped toolkit package; Levenshtein comparison to 'pino' is a stable false positive. ai
typosquat typosquat.levenshtein:got AI (typosquat): @actions/io is GitHub's official scoped toolkit package; Levenshtein comparison to 'got' is a stable false positive. ai
typosquat typosquat.levenshtein:pg AI (typosquat): @actions/io is GitHub's official scoped toolkit package; Levenshtein comparison to 'pg' is a stable false positive. ai
typosquat typosquat.levenshtein:qs AI (typosquat): @actions/io is GitHub's official scoped toolkit package; Levenshtein comparison to 'qs' is a stable false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @actions/io is GitHub's official scoped toolkit package; Levenshtein comparison to 'joi' is a stable false positive. ai

Versions (showing 11 of 11)

Version Deps Published
3.0.2 0 / 0
3.0.1 0 / 0
3.0.0 0 / 0
2.0.0 0 / 0
1.1.3 0 / 0
1.1.2 0 / 0
1.1.1 0 / 0
1.1.0 0 / 0
1.0.2 0 / 0
1.0.1 0 / 0
1.0.0 0 / 0