← Home

@pnpm/tarball-fetcher

13
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

pnpmuserzkochan

Keywords

pnpmpnpm10fetchertarball

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@pnpm/fs.packlist AI (dependencies): Internal @pnpm monorepo package co-published with this package; not a third-party risk. ai
dependencies unvetted-dep:@pnpm/fetcher-base AI (dependencies): Internal @pnpm monorepo package co-published with this package; not a third-party risk. ai
dependencies unvetted-dep:@pnpm/prepare-package AI (dependencies): Internal @pnpm monorepo package co-published with this package; not a third-party risk. ai
phantom-deps phantom-dep:ramda AI (phantom-deps): ramda is aliased to @pnpm/ramda in package.json — a pnpm-maintained fork. The phantom-dep signal is a false positive for this aliasing pattern. ai
phantom-deps phantom-dep:@pnpm/types AI (phantom-deps): @pnpm/types is a type-only package from the same org scope, used for TypeScript declarations. Not directly imported at runtime is expected behavior. ai
phantom-deps phantom-dep:p-map-values AI (phantom-deps): p-map-values is referenced in config files but not directly imported — consistent with being used indirectly. Benign for this package. ai

Versions (showing 13 of 13)

Version Deps Published
1006.0.7 14 / 15
1006.0.6 14 / 15
1006.0.5 14 / 15
1006.0.3 14 / 15
1006.0.2 14 / 15
1006.0.1 14 / 15
1006.0.0 14 / 15
1005.0.0 14 / 15
1004.0.1 13 / 15
1004.0.0 13 / 15
1003.0.3 13 / 15
1003.0.2 13 / 15
1003.0.1 13 / 15

v1006.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1006.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1006.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1006.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1006.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1006.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1006.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1005.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1004.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1004.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1003.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1003.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1003.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.