← Home

@vercel/go

22
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matheussmatt.strakavercel-release-botzeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:got AI (typosquat): @vercel/go is the official Vercel Go runtime, not a typosquat of 'got'; scoped under verified @vercel org. ai
typosquat typosquat.levenshtein:glob AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'glob' is coincidental. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'koa' is coincidental. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'pg' is coincidental. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'qs' is coincidental. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'joi' is coincidental. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Legitimate @vercel scoped package; Levenshtein match to 'zod' is coincidental. ai

Versions (showing 22 of 22)

Version Deps Published
3.8.0 0 / 17
3.7.1 0 / 17
3.7.0 0 / 17
3.6.0 0 / 18
3.5.0 0 / 19
3.4.7 0 / 19
3.4.6 0 / 19
3.4.5 0 / 19
3.4.4 0 / 19
3.4.3 0 / 19
3.4.2 0 / 19
3.4.1 0 / 19
3.4.0 0 / 19
3.3.5 0 / 19
3.3.4 0 / 20
3.3.3 0 / 20
3.3.2 0 / 20
3.3.1 0 / 20
3.3.0 0 / 20
3.2.4 0 / 20
3.2.3 0 / 20
3.2.2 0 / 20

v3.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.7

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.6

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.5

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.4

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.3

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.2

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.1

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.5

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.4

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.3

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.2

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.1

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.4

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.3

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.2

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'got' typosquat

Package name '@vercel/go' is 1 edit(s) away from popular package 'got'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.