@anolilab/semantic-release-clean-package-json
Clean package.json before publish by removing unnecessary properties.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions CI with SLSA provenance attestation is a legitimate and expected supply-chain improvement for this package. | ai | |
| dependencies | unvetted-dep:@visulima/fs | AI (dependencies): Same anolilab/visulima ecosystem; stable dependency across multiple versions of this package. | ai | |
| dependencies | unvetted-dep:@visulima/path | AI (dependencies): Same anolilab/visulima ecosystem; stable dependency across multiple versions of this package. | ai | |
| phantom-deps | phantom-dep:type-fest | AI (phantom-deps): Compiled ESM package; types-only usage in dist won't show direct imports in source scan. | ai | |
| phantom-deps | phantom-dep:@semantic-release/error | AI (phantom-deps): Compiled ESM package; imports resolved in dist, not raw source files. | ai | |
| phantom-deps | phantom-dep:@visulima/fs | AI (phantom-deps): Compiled ESM package; imports resolved in dist, not raw source files. | ai | |
| phantom-deps | phantom-dep:@visulima/path | AI (phantom-deps): Compiled ESM package; imports resolved in dist, not raw source files. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 5.5.13 | 4 / 0 | |
| 5.5.12 | 4 / 0 | |
| 5.5.11 | 4 / 0 | |
| 5.5.10 | 4 / 0 | |
| 5.5.9 | 4 / 0 | |
| 5.5.8 | 4 / 0 | |
| 5.5.7 | 4 / 0 | |
| 5.5.6 | 4 / 0 | |
| 5.5.5 | 4 / 0 | |
| 5.5.4 | 4 / 0 | |
| 5.5.3 | 4 / 0 | |
| 5.5.2 | 4 / 0 | |
| 5.5.1 | 4 / 0 | |
| 5.5.0 | 4 / 0 | |
| 5.4.0 | 4 / 0 | |
| 5.3.0 | 4 / 0 | |
| 5.2.0 | 4 / 0 | |
| 5.1.0 | 4 / 0 | |
| 5.0.0 | 4 / 0 | |
| 4.2.2 | 4 / 0 | |
| 4.2.1 | 4 / 0 | |
| 4.2.0 | 4 / 0 | |
| 4.1.0 | 4 / 0 | |
| 4.0.0 | 4 / 0 | |
| 3.0.5 | 3 / 0 |
v5.5.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.3
2 findingsThis version was published by a different npm account than previous versions on 2026-04-27. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.2
2 findingsThis version was published by a different npm account than previous versions on 2026-04-26. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.1
2 findingsThis version was published by a different npm account than previous versions on 2026-04-26. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.0
2 findingsThis version was published by a different npm account than previous versions on 2026-04-08. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.4.0
2 findingsThis version was published by a different npm account than previous versions on 2026-04-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.0
2 findingsThis version was published by a different npm account than previous versions on 2026-02-02. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.0
2 findingsThis version was published by a different npm account than previous versions on 2026-01-13. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
2 findingsThis version was published by a different npm account than previous versions on 2026-01-08. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.