← Home

@3-/captcha-darwin-x64

This is the **x86_64-apple-darwin** binary for `@3-/captcha`

18
Versions
MulanPSL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

i18n-now

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher reflects CI/CD automation; consistent repo URL and SLSA attestation confirm legitimate origin. ai
npm-metadata bundled-binaries AI (npm-metadata): Platform-specific native addon shard; .node binary is the entire purpose of this package. ai
bogus-package bogus-package AI (bogus-package): Auto-generated platform shard packages routinely lack README, keywords, and deps — not a spam signal here. ai

Versions (showing 18 of 18)

Version Deps Published
0.1.49 0 / 0
0.1.48 0 / 0
0.1.47 0 / 0
0.1.46 0 / 0
0.1.44 0 / 0
0.1.43 0 / 0
0.1.42 0 / 0
0.1.41 0 / 0
0.1.40 0 / 0
0.1.39 0 / 0
0.1.38 0 / 0
0.1.37 0 / 0
0.1.36 0 / 0
0.1.35 0 / 0
0.1.32 0 / 0
0.1.17 0 / 0
0.1.14 0 / 0
0.1.13 0 / 0

v0.1.49

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.48

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-03) provenance

This version was published by a different npm account than previous versions on 2026-05-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.47

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-03) provenance

This version was published by a different npm account than previous versions on 2026-05-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.46

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-03) provenance

This version was published by a different npm account than previous versions on 2026-05-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.44

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-03) provenance

This version was published by a different npm account than previous versions on 2026-05-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.43

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-03) provenance

This version was published by a different npm account than previous versions on 2026-05-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.42

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-03) provenance

This version was published by a different npm account than previous versions on 2026-05-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.41

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-02) provenance

This version was published by a different npm account than previous versions on 2026-05-02. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.40

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-02) provenance

This version was published by a different npm account than previous versions on 2026-05-02. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.39

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-02) provenance

This version was published by a different npm account than previous versions on 2026-05-02. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.38

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-02) provenance

This version was published by a different npm account than previous versions on 2026-05-02. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.37

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-02) provenance

This version was published by a different npm account than previous versions on 2026-05-02. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.36

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-01) provenance

This version was published by a different npm account than previous versions on 2026-05-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.35

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-01) provenance

This version was published by a different npm account than previous versions on 2026-05-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.32

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • captcha.darwin-x64.node

HIGH Publisher changed: i18n-now → GitHub Actions (on 2026-05-01) provenance

This version was published by a different npm account than previous versions on 2026-05-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.