@beyonk/uploader
A complete file upload system.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@beyonk/icons | AI (phantom-deps): Same-org package likely re-exported via index; not directly imported but legitimately declared. | ai | |
| email-domain | unclaimed-email:desirableobjects.co.uk | AI (email-domain): Long-established package; publisher has clean track record; no code changes introduced alongside this finding. | ai | |
| provenance | no-provenance | AI (provenance): Established @beyonk org package; missing provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:svelte-dnd-action | AI (phantom-deps): svelte-dnd-action is a declared runtime dependency; Svelte component usage may not be detected as a direct import by the analyzer. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 8.4.5 | 2 / 15 | |
| 8.4.4 | 2 / 15 | |
| 8.4.3 | 2 / 16 | |
| 8.4.2 | 2 / 16 | |
| 8.4.1 | 2 / 16 | |
| 8.4.0 | 2 / 16 | |
| 8.3.5 | 2 / 15 | |
| 8.3.4 | 3 / 14 | |
| 8.3.3 | 3 / 14 | |
| 8.3.2 | 1 / 16 | |
| 8.3.1 | 1 / 16 | |
| 8.3.0 | 1 / 16 | |
| 8.2.0 | 1 / 16 | |
| 8.1.0 | 1 / 16 | |
| 8.0.9 | 0 / 16 | |
| 8.0.8 | 0 / 18 | |
| 8.0.7 | 0 / 18 | |
| 8.0.6 | 0 / 18 | |
| 8.0.5 | 0 / 18 | |
| 8.0.4 | 0 / 18 | |
| 8.0.3 | 0 / 18 | |
| 8.0.2 | 0 / 18 | |
| 8.0.1 | 0 / 18 | |
| 8.0.0 | 0 / 18 |
v8.4.5
2 findingsMaintainer email '[email protected]' uses domain 'desirableobjects.co.uk' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (svargas-dev) than the most recent previously approved version (alex.dilley) on 2026-03-12, but svargas-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.9
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (svargas-dev) than the most recent previously approved version (alex.dilley) on 2026-02-12, but svargas-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (svargas-dev) than the most recent previously approved version (alex.dilley) on 2026-01-13, but svargas-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.5
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (svargas-dev) than the most recent previously approved version (alex.dilley) on 2026-01-09, but svargas-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.