← Home

ipfs-unixfs-exporter

9
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

achingbrainipfs-npm-publisher-botnpm-service-account-ipfs

Keywords

IPFS

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Migration from npm-service-account-ipfs to GitHub Actions CI/CD is a documented IPFS ecosystem transition; SLSA provenance attestation confirms builds originate from the official ipfs/js-ipfs-unixfs repo. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms the publish originated from the official GitHub repo, ruling out account takeover as the cause of dormancy-then-publish. ai
dependencies unvetted-dep:it-to-buffer AI (dependencies): it-to-buffer is a well-known IPFS ecosystem utility package; stable long-term dependency of this package with no suspicious signals. ai
dependencies unvetted-dep:hamt-sharding AI (dependencies): hamt-sharding is a core IPFS/multiformats ecosystem package used for HAMT directory sharding; stable long-term dependency with no suspicious signals. ai
dependencies unvetted-dep:@multiformats/murmur3 AI (dependencies): @multiformats/murmur3 is an official multiformats org package; stable long-term dependency with no suspicious signals. ai

Versions (showing 9 of 9)

Version Deps Published
16.0.2 16 / 17
16.0.1 16 / 17
16.0.0 16 / 17
15.0.4 16 / 17
15.0.3 16 / 17
15.0.2 16 / 17
15.0.1 15 / 18
15.0.0 15 / 18
14.0.2 17 / 16

v16.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.