@vercel/rust
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Official Vercel runtime; missing description is a cosmetic issue, not a malice signal. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Verified Vercel org package with SLSA provenance; bogus-package signals are false positives here. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is a declared runtime dependency; phantom-dep heuristic misfires here. | ai | |
| typosquat | typosquat.levenshtein:nuxt | AI (typosquat): Official @vercel scoped package; coincidental edit-distance match, not a typosquat. | ai | |
| typosquat | typosquat.levenshtein:jest | AI (typosquat): Official @vercel scoped package; coincidental edit-distance match, not a typosquat. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 1.3.0 | 2 / 11 | |
| 1.2.0 | 2 / 13 | |
| 1.1.1 | 2 / 14 | |
| 1.1.0 | 2 / 14 | |
| 1.0.6 | 2 / 14 | |
| 1.0.5 | 2 / 14 | |
| 1.0.4 | 2 / 14 | |
| 1.0.3 | 2 / 14 | |
| 1.0.2 | 3 / 17 | |
| 1.0.1 | 3 / 17 |
v1.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.5
2 findingsMaintainer email '[email protected]' uses domain 'magic.io' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.