@adobe/spacecat-shared-utils
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Adobe org migrated publishing to GitHub Actions CI/CD; SLSA provenance attestation confirms supply chain integrity. | ai | |
| dependencies | unvetted-dep:@adobe/spacecat-shared-ims-client | AI (dependencies): First-party Adobe/spacecat package from the same org and publisher lineage. | ai | |
| dependencies | unvetted-dep:aws-xray-sdk | AI (dependencies): aws-xray-sdk is an official AWS observability SDK; no malware indicators, stable dependency for this package. | ai | |
| dependencies | unvetted-dep:@json2csv/plainjs | AI (dependencies): @json2csv/plainjs is a well-known CSV conversion library; no malware indicators, stable dependency for this package. | ai |
Versions (showing 51 of 53)
| Version | Deps | Published |
|---|---|---|
| 1.116.6 | 14 / 10 | |
| 1.116.5 | 14 / 10 | |
| 1.116.4 | 14 / 10 | |
| 1.116.3 | 14 / 10 | |
| 1.116.2 | 14 / 10 | |
| 1.116.1 | 14 / 10 | |
| 1.116.0 | 14 / 10 | |
| 1.115.4 | 14 / 10 | |
| 1.114.0 | 13 / 10 | |
| 1.112.4 | 13 / 10 | |
| 1.112.0 | 13 / 10 | |
| 1.111.0 | 13 / 9 | |
| 1.110.0 | 13 / 9 | |
| 1.109.0 | 13 / 9 | |
| 1.107.0 | 13 / 9 | |
| 1.105.0 | 13 / 9 | |
| 1.104.0 | 13 / 9 | |
| 1.103.0 | 13 / 9 | |
| 1.102.1 | 13 / 9 | |
| 1.102.0 | 13 / 9 | |
| 1.100.0 | 13 / 9 | |
| 1.98.0 | 13 / 9 | |
| 1.96.3 | 13 / 9 | |
| 1.96.2 | 13 / 9 | |
| 1.96.1 | 13 / 9 | |
| 1.96.0 | 13 / 9 | |
| 1.92.0 | 13 / 9 | |
| 1.91.0 | 13 / 9 | |
| 1.90.2 | 13 / 9 | |
| 1.88.0 | 13 / 9 | |
| 1.86.0 | 13 / 9 | |
| 1.85.1 | 13 / 9 | |
| 1.84.0 | 13 / 9 | |
| 1.83.0 | 13 / 9 | |
| 1.81.1 | 12 / 9 | |
| 1.81.0 | 12 / 9 | |
| 1.78.1 | 12 / 9 | |
| 1.77.0 | 12 / 9 | |
| 1.76.0 | 12 / 9 | |
| 1.72.1 | 12 / 9 | |
| 1.70.1 | 12 / 9 | |
| 1.70.0 | 12 / 9 | |
| 1.69.1 | 12 / 9 | |
| 1.67.0 | 12 / 9 | |
| 1.66.1 | 12 / 9 | |
| 1.66.0 | 14 / 9 | |
| 1.53.0 | 11 / 9 | |
| 1.44.0 | 9 / 8 | |
| 1.42.1 | 9 / 8 | |
| 1.41.2 | 9 / 8 | |
| 1.37.3 | 6 / 9 |
v1.116.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.116.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.116.4
2 findingsThis version was published by a different npm account than previous versions on 2026-05-29. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.116.3
2 findingsThis version was published by a different npm account than previous versions on 2026-05-27. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.116.2
2 findingsThis version was published by a different npm account than previous versions on 2026-05-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.116.1
2 findingsThis version was published by a different npm account than previous versions on 2026-05-22. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.116.0
2 findingsThis version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.115.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.114.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.112.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.111.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.110.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.109.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.107.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.104.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.103.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.102.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.102.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.100.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.98.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.96.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.96.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.96.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.96.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.92.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.91.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.90.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.88.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.86.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.85.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.84.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.83.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.81.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.81.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.67.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.