← Home

@adobe/spacecat-shared-utils

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

marbectripodgarthdblazdadobe-adminpatrickfultontrieloffkrisnyedcpfsdknatebaldwindevongovettaspro83symanovidpfisterstefan-guggisbergrofekptdobeadobehallsfullcolorcoderdjaeggidylandepassmhaackamol-anandstopp-adobenamaroradotenduh_schmidtasthabh23zdahbituicufmeschbe

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Adobe org migrated publishing to GitHub Actions CI/CD; SLSA provenance attestation confirms supply chain integrity. ai
dependencies unvetted-dep:@adobe/spacecat-shared-ims-client AI (dependencies): First-party Adobe/spacecat package from the same org and publisher lineage. ai
dependencies unvetted-dep:aws-xray-sdk AI (dependencies): aws-xray-sdk is an official AWS observability SDK; no malware indicators, stable dependency for this package. ai
dependencies unvetted-dep:@json2csv/plainjs AI (dependencies): @json2csv/plainjs is a well-known CSV conversion library; no malware indicators, stable dependency for this package. ai

Versions (showing 100 of 233)

Version Deps Published
1.125.0 14 / 10
1.124.1 14 / 10
1.124.0 14 / 10
1.123.1 14 / 10
1.123.0 14 / 10
1.122.1 14 / 10
1.122.0 14 / 10
1.121.0 14 / 10
1.120.1 14 / 10
1.120.0 14 / 10
1.119.3 14 / 10
1.119.2 14 / 10
1.119.1 14 / 10
1.119.0 14 / 10
1.118.0 14 / 10
1.117.0 14 / 10
1.116.6 14 / 10
1.116.5 14 / 10
1.116.4 14 / 10
1.116.3 14 / 10
1.116.2 14 / 10
1.116.1 14 / 10
1.116.0 14 / 10
1.115.4 14 / 10
1.115.3 13 / 10
1.115.2 13 / 10
1.115.1 13 / 10
1.115.0 13 / 10
1.114.0 13 / 10
1.113.0 13 / 10
1.112.5 13 / 10
1.112.4 13 / 10
1.112.3 13 / 10
1.112.2 13 / 10
1.112.1 13 / 10
1.112.0 13 / 10
1.111.0 13 / 9
1.110.0 13 / 9
1.109.0 13 / 9
1.108.0 13 / 9
1.107.0 13 / 9
1.106.1 13 / 9
1.106.0 13 / 9
1.105.1 13 / 9
1.105.0 13 / 9
1.104.0 13 / 9
1.103.0 13 / 9
1.102.1 13 / 9
1.102.0 13 / 9
1.101.0 13 / 9
1.100.1 13 / 9
1.100.0 13 / 9
1.99.0 13 / 9
1.98.1 13 / 9
1.98.0 13 / 9
1.97.0 13 / 9
1.96.3 13 / 9
1.96.2 13 / 9
1.96.1 13 / 9
1.96.0 13 / 9
1.95.0 13 / 9
1.94.0 13 / 9
1.93.0 13 / 9
1.92.0 13 / 9
1.91.0 13 / 9
1.90.3 13 / 9
1.90.2 13 / 9
1.90.1 13 / 9
1.90.0 13 / 9
1.89.1 13 / 9
1.89.0 13 / 9
1.88.0 13 / 9
1.87.1 13 / 9
1.87.0 13 / 9
1.86.0 13 / 9
1.85.2 13 / 9
1.85.1 13 / 9
1.85.0 13 / 9
1.84.0 13 / 9
1.83.0 13 / 9
1.82.3 13 / 9
1.82.2 13 / 9
1.82.1 13 / 9
1.82.0 13 / 9
1.81.1 12 / 9
1.81.0 12 / 9
1.80.0 12 / 9
1.79.0 12 / 9
1.78.1 12 / 9
1.78.0 12 / 9
1.77.1 12 / 9
1.77.0 12 / 9
1.76.0 12 / 9
1.75.0 12 / 9
1.74.0 12 / 9
1.73.1 12 / 9
1.73.0 12 / 9
1.72.1 12 / 9
1.72.0 12 / 9
1.71.0 12 / 9
Showing 100 of 233 Next page →

v1.125.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.124.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.124.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.123.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.115.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.113.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.108.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.106.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.106.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.105.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.101.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.100.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.99.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.98.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.97.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.95.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.90.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.90.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.90.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.89.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.89.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.87.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.87.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.85.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.85.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.82.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: djaeggi → adobe-admin (on 2025-12-10, known maintainer) provenance

This version was published by a different npm account (adobe-admin) than the most recent previously approved version (djaeggi) on 2025-12-10, but adobe-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.82.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.82.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.82.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.80.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.79.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.78.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.75.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.74.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.72.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.