← Home

@pnpm/package-store

A storage for packages

15
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

pnpmuserzkochan

Keywords

pnpmpnpm10cachecentral storageglobal storemaching storepackagesstoragestore

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): pnpm monorepo transitioned to GitHub Actions CI/CD publishing; SLSA provenance attestation confirms legitimate pipeline. This is a stable, expected change for this package. ai
dependencies unvetted-dep:@pnpm/fetcher-base AI (dependencies): Internal pnpm monorepo package published by the same trusted maintainer (zkochan); not a third-party dependency. ai
dependencies unvetted-dep:@pnpm/create-cafs-store AI (dependencies): Internal pnpm monorepo package published by the same trusted maintainer (zkochan); not a third-party dependency. ai
dependencies unvetted-dep:@pnpm/package-requester AI (dependencies): Internal pnpm monorepo package published by the same trusted maintainer (zkochan); not a third-party dependency. ai
dependencies unvetted-dep:@pnpm/store-controller-types AI (dependencies): Internal pnpm monorepo package published by the same trusted maintainer (zkochan); not a third-party dependency. ai
dependencies unvetted-dep:@pnpm/store.cafs AI (dependencies): Internal pnpm monorepo package published by the same trusted maintainer (zkochan); not a third-party dependency. ai
dependencies unvetted-dep:@pnpm/crypto.hash AI (dependencies): Internal pnpm monorepo package published by the same trusted maintainer (zkochan); not a third-party dependency. ai
dependencies unvetted-dep:@pnpm/resolver-base AI (dependencies): Internal pnpm monorepo package published by the same trusted maintainer (zkochan); not a third-party dependency. ai
phantom-deps phantom-dep:@pnpm/store.cafs AI (phantom-deps): Same-org @pnpm/store.cafs is a declared dependency in package.json; phantom detection is a false positive for this pnpm monorepo package. ai
phantom-deps phantom-dep:ramda AI (phantom-deps): ramda is aliased to @pnpm/ramda in package.json dependencies — the phantom-dep analyzer doesn't recognize the npm alias pattern. Stable false positive for this package. ai
phantom-deps phantom-dep:@pnpm/types AI (phantom-deps): Same-org @pnpm/types is a legitimate declared dependency used as a type-only import; phantom detection is a false positive for this pnpm monorepo package. ai

Versions (showing 15 of 15)

Version Deps Published
1007.1.7 15 / 7
1007.1.6 15 / 7
1007.1.5 15 / 7
1007.1.4 15 / 7
1007.1.3 15 / 7
1007.1.2 15 / 7
1007.1.1 15 / 7
1007.1.0 15 / 7
1007.0.0 11 / 7
1006.0.0 11 / 7
1005.0.1 11 / 7
1005.0.0 11 / 7
1004.0.3 11 / 7
1004.0.2 11 / 7
1004.0.1 11 / 7

v1007.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1007.1.6

2 findings
HIGH Publisher changed: zkochan → GitHub Actions (on 2026-03-24) provenance

This version was published by a different npm account than previous versions on 2026-03-24. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1007.1.5

2 findings
HIGH Publisher changed: zkochan → GitHub Actions (on 2026-03-07) provenance

This version was published by a different npm account than previous versions on 2026-03-07. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1007.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1007.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1007.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1007.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1007.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1007.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1006.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1005.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1005.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1004.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1004.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1004.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.