@pulumi/pulumi
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@pulumi/query | AI (dependencies): First-party Pulumi package; stable dependency across all @pulumi/pulumi versions. | ai | |
| phantom-deps | phantom-dep:pkg-dir | AI (phantom-deps): Declared but not directly imported; consistent with build/config tooling in this package. | ai | |
| phantom-deps | phantom-dep:@types/tmp | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:package-directory | AI (phantom-deps): package-directory is legitimately declared and used in build/config files; expected for SDK packages. | ai | |
| phantom-deps | phantom-dep:@types/google-protobuf | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:@types/semver | AI (phantom-deps): @types/* packages are loaded by TypeScript convention; properly declared in dependencies. | ai | |
| phantom-deps | phantom-dep:picomatch | AI (phantom-deps): picomatch is legitimately declared and used in build/config files; expected for SDK packages. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is used to load optional peer deps (ts-node, typescript) by name at runtime — a documented pattern for optional peer dependency loading in this SDK. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): getValue_asB64() is standard protobuf API for accessing binary fields over gRPC; not obfuscation or payload hiding. | ai |
Versions (showing 100 of 141)
| Version | Deps | Published |
|---|---|---|
| 3.246.0 | 27 / 22 | |
| 3.245.0 | 27 / 22 | |
| 3.244.0 | 27 / 22 | |
| 3.243.0 | 27 / 22 | |
| 3.242.0 | 27 / 22 | |
| 3.241.0 | 27 / 22 | |
| 3.239.0 | 27 / 22 | |
| 3.238.0 | 27 / 22 | |
| 3.237.0 | 27 / 22 | |
| 3.236.0 | 27 / 22 | |
| 3.235.0 | 27 / 22 | |
| 3.234.0 | 27 / 22 | |
| 3.233.0 | 27 / 22 | |
| 3.232.0 | 27 / 22 | |
| 3.231.0 | 27 / 22 | |
| 3.230.0 | 29 / 22 | |
| 3.229.0 | 29 / 22 | |
| 3.228.0 | 29 / 22 | |
| 3.227.0 | 29 / 22 | |
| 3.226.0 | 29 / 22 | |
| 3.225.1 | 29 / 22 | |
| 3.225.0 | 29 / 22 | |
| 3.224.0 | 28 / 22 | |
| 3.223.0 | 28 / 22 | |
| 3.222.0 | 28 / 22 | |
| 3.221.0 | 28 / 22 | |
| 3.220.0 | 28 / 22 | |
| 3.219.0 | 28 / 22 | |
| 3.218.0 | 28 / 22 | |
| 3.217.1 | 28 / 22 | |
| 3.217.0 | 28 / 22 | |
| 3.216.0 | 28 / 22 | |
| 3.215.0 | 28 / 22 | |
| 3.214.1 | 28 / 22 | |
| 3.214.0 | 28 / 22 | |
| 3.213.0 | 28 / 22 | |
| 3.212.0 | 28 / 22 | |
| 3.211.0 | 28 / 22 | |
| 3.210.0 | 28 / 22 | |
| 3.209.0 | 28 / 23 | |
| 3.208.0 | 28 / 23 | |
| 3.207.0 | 28 / 23 | |
| 3.206.0 | 28 / 23 | |
| 3.205.0 | 28 / 23 | |
| 3.204.0 | 28 / 23 | |
| 3.203.0 | 28 / 23 | |
| 3.202.0 | 28 / 23 | |
| 3.201.0 | 28 / 23 | |
| 3.200.0 | 28 / 23 | |
| 3.199.0 | 28 / 23 | |
| 3.198.0 | 28 / 23 | |
| 3.197.0 | 28 / 23 | |
| 3.196.0 | 28 / 23 | |
| 3.195.0 | 28 / 23 | |
| 3.194.0 | 28 / 23 | |
| 3.193.0 | 28 / 23 | |
| 3.192.0 | 28 / 23 | |
| 3.191.0 | 28 / 23 | |
| 3.190.0 | 28 / 23 | |
| 3.189.0 | 28 / 23 | |
| 3.188.0 | 28 / 23 | |
| 3.187.0 | 28 / 23 | |
| 3.186.0 | 28 / 23 | |
| 3.185.0 | 28 / 23 | |
| 3.184.0 | 28 / 23 | |
| 3.183.0 | 28 / 23 | |
| 3.182.0 | 28 / 23 | |
| 3.181.0 | 28 / 23 | |
| 3.180.0 | 28 / 23 | |
| 3.178.0 | 28 / 23 | |
| 3.177.0 | 28 / 23 | |
| 3.176.0 | 28 / 23 | |
| 3.175.0 | 28 / 23 | |
| 3.174.0 | 28 / 23 | |
| 3.173.0 | 28 / 23 | |
| 3.172.0 | 28 / 23 | |
| 3.171.0 | 28 / 23 | |
| 3.170.0 | 28 / 23 | |
| 3.169.0 | 28 / 23 | |
| 3.168.0 | 28 / 23 | |
| 3.167.0 | 28 / 23 | |
| 3.166.0 | 28 / 23 | |
| 3.165.0 | 28 / 23 | |
| 3.163.0 | 28 / 23 | |
| 3.162.0 | 28 / 23 | |
| 3.161.0 | 28 / 23 | |
| 3.160.0 | 29 / 23 | |
| 3.159.0 | 29 / 23 | |
| 3.158.0 | 29 / 23 | |
| 3.157.0 | 29 / 23 | |
| 3.156.0 | 29 / 23 | |
| 3.155.0 | 29 / 23 | |
| 3.154.0 | 29 / 23 | |
| 3.153.1 | 30 / 22 | |
| 3.153.0 | 30 / 22 | |
| 3.152.0 | 30 / 22 | |
| 3.151.0 | 30 / 22 | |
| 3.150.0 | 30 / 22 | |
| 3.149.0 | 30 / 22 | |
| 3.148.0 | 30 / 22 |
v3.246.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.245.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.244.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.243.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.242.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.241.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.239.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.238.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.237.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.236.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.235.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.234.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.233.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.232.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.231.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.230.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.229.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.228.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.227.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.226.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.225.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.225.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.224.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.223.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.222.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.221.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.220.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.219.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.218.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.217.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.217.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.216.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.215.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.214.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.214.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.213.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.212.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.211.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.210.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.209.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.208.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.207.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.206.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.205.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.204.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.203.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.202.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.201.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.196.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.191.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.189.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.188.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.187.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.186.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.185.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.178.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.172.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.169.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.167.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.165.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.163.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.162.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.161.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.160.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.159.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.158.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.157.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.156.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.155.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.154.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.153.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.153.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.152.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.151.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.150.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.149.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.148.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.