@argos-ci/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Manual→CI/CD transition with SLSA attestation; legitimate for this package. | ai | |
| provenance | regressed-provenance | AI (provenance): Manual publish by established maintainer neoziro; no code changes vs prior version. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped @argos-ci package; not a typosquat of cors — different namespace and purpose entirely. | ai | |
| dependencies | unvetted-dep:@argos-ci/util | AI (dependencies): Same-org sibling package; not an external unvetted dependency. | ai | |
| dependencies | unvetted-dep:@argos-ci/api-client | AI (dependencies): Same-org sibling package; not an external unvetted dependency. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 6.7.0 | 9 / 9 | |
| 6.6.2 | 9 / 9 | |
| 6.6.1 | 9 / 9 | |
| 6.6.0 | 9 / 9 | |
| 6.5.3 | 9 / 9 | |
| 6.5.0 | 9 / 9 | |
| 6.4.0 | 9 / 9 | |
| 6.3.0 | 9 / 9 | |
| 6.2.3 | 9 / 9 | |
| 6.2.2 | 9 / 9 | |
| 6.2.1 | 8 / 9 | |
| 6.2.0 | 8 / 9 | |
| 6.1.1 | 8 / 9 | |
| 6.1.0 | 8 / 9 | |
| 6.0.3 | 8 / 9 | |
| 6.0.2 | 8 / 9 | |
| 6.0.1 | 8 / 9 | |
| 6.0.0 | 8 / 9 | |
| 5.3.1 | 8 / 9 | |
| 5.3.0 | 8 / 9 | |
| 5.2.1 | 8 / 9 | |
| 5.2.0 | 8 / 9 | |
| 5.1.3 | 8 / 9 | |
| 5.1.2 | 8 / 8 | |
| 5.1.1 | 8 / 8 | |
| 5.1.0 | 8 / 8 | |
| 5.0.4 | 8 / 8 | |
| 5.0.3 | 8 / 8 | |
| 5.0.2 | 8 / 8 | |
| 5.0.1 | 8 / 8 | |
| 5.0.0 | 8 / 8 |
v6.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (neoziro) on 2026-07-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v6.6.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version was published by a different npm account than previous versions on unknown date. This could indicate a legitimate maintainer transition or an account compromise.
v6.5.3
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account (neoziro) than the most recent previously approved version (GitHub Actions) on 2026-07-09, but neoziro is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.