← Home

@blocknote/core

83
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

yousefedmatthewlipskinperez0111

Keywords

reactjavascripteditortypescriptprosemirrorwysiwygrich-text-editornotionyjsblock-basedtiptap

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): Core tiptap peer dep, used transitively by editor extensions. ai
phantom-deps phantom-dep:prosemirror-schema-list AI (phantom-deps): Core prosemirror extension used in editor, bundled build hides import. ai
phantom-deps phantom-dep:prosemirror-keymap AI (phantom-deps): Core prosemirror extension used in editor, bundled build hides import. ai
phantom-deps phantom-dep:prosemirror-gapcursor AI (phantom-deps): Core prosemirror extension used in editor, bundled build hides import. ai
phantom-deps phantom-dep:prosemirror-commands AI (phantom-deps): Core prosemirror extension used in editor, bundled build hides import. ai
phantom-deps phantom-dep:prosemirror-history AI (phantom-deps): Core prosemirror extension used in editor, bundled build hides import. ai
phantom-deps phantom-dep:prosemirror-dropcursor AI (phantom-deps): Core prosemirror extension used in editor, bundled build hides import. ai
phantom-deps phantom-dep:y-protocols AI (phantom-deps): Yjs collaboration dep used via bundling, not direct import scan. ai
phantom-deps phantom-dep:y-prosemirror AI (phantom-deps): Yjs collaboration dep used via bundling, not direct import scan. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Used indirectly via bundled build; common FP for this package's build system. ai
phantom-deps phantom-dep:@emotion/utils AI (phantom-deps): Legit transitive dep, false positive from heuristic scan. ai
phantom-deps phantom-dep:@tiptap/extension-collaboration-cursor AI (phantom-deps): Optional tiptap extension declared for consumers, not directly imported. ai
phantom-deps phantom-dep:@tiptap/extension-collaboration AI (phantom-deps): Optional tiptap extension declared for consumers, not directly imported. ai
phantom-deps phantom-dep:@emotion/serialize AI (phantom-deps): Legit transitive dep, false positive from heuristic scan. ai
phantom-deps phantom-dep:@emotion/cache AI (phantom-deps): Legit transitive dep for prosemirror styling, not malicious. ai
source-diff obfuscated-file:dist/en-C5Z4Ag9_.cjs AI (source-diff): Minified locale bundle, readable data. ai
source-diff obfuscated-file:dist/y.cjs AI (source-diff): Minified bundle output. ai
source-diff obfuscated-file:dist/src-OfbaVbMw.cjs AI (source-diff): Minified bundle output. ai
source-diff obfuscated-file:dist/src-DTF83Cl9.js AI (source-diff): ESM bundle output, named imports intact. ai
source-diff obfuscated-file:dist/extensions-Ghr9QqqR.cjs AI (source-diff): Minified bundle output. ai
source-diff obfuscated-file:dist/blocks-BqHv0xhc.cjs AI (source-diff): Minified rollup bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/defaultBlocks-BX6UxQa8.cjs AI (source-diff): Minified build output; benign. ai
source-diff obfuscated-file:dist/TrailingNode-Du4SNHun.cjs AI (source-diff): Minified build output; benign. ai
source-diff obfuscated-file:dist/BlockNoteSchema-CBNkNhkw.cjs AI (source-diff): Minified build output, readable module graph, no malicious behavior. ai
source-diff obfuscated-file:dist/defaultBlocks-DLJ4Q1_J.cjs AI (source-diff): Minified build output chunk. ai
source-diff obfuscated-file:dist/TrailingNode-CRHrgOnK.cjs AI (source-diff): Minified build output chunk. ai
source-diff obfuscated-file:dist/BlockNoteSchema-B4gm-Qco.cjs AI (source-diff): Minified build output chunk. ai
source-diff obfuscated-file:dist/defaultBlocks-CSB5GiAu.cjs AI (source-diff): Minified build output. ai
source-diff obfuscated-file:dist/TrailingNode-DHOdUVUO.cjs AI (source-diff): Minified build output. ai
source-diff obfuscated-file:dist/BlockNoteSchema-CwhtPpVC.cjs AI (source-diff): Minified build output, no obfuscation signature. ai
source-diff obfuscated-file:dist/TrailingNode-DPu6X9ym.cjs AI (source-diff): Minified build chunk. ai
source-diff obfuscated-file:dist/BlockNoteSchema-CzZbr4Ed.cjs AI (source-diff): Minified build chunk of declared source. ai
source-diff obfuscated-file:dist/defaultBlocks-D1cc0lV9.cjs AI (source-diff): Minified build chunk. ai
source-diff obfuscated-file:dist/TrailingNode-W7GJVng5.cjs AI (source-diff): Minified build output, benign. ai
source-diff obfuscated-file:dist/BlockNoteSchema-qt4Czo0-.cjs AI (source-diff): Minified build output, benign. ai
source-diff obfuscated-file:dist/defaultBlocks-IsUGVZIq.cjs AI (source-diff): Minified build output, benign. ai
source-diff obfuscated-file:dist/TrailingNode-D-CZ76FS.cjs AI (source-diff): Minified build output. ai
source-diff obfuscated-file:dist/BlockNoteSchema-DmFDeA0n.cjs AI (source-diff): Minified build output, readable logic. ai
source-diff obfuscated-file:dist/defaultBlocks-DosClM5E.cjs AI (source-diff): Minified build output. ai
provenance publisher-changed AI (provenance): Move to GitHub Actions CI publish with SLSA attestation; benign. ai
source-diff obfuscated-file:dist/defaultBlocks-BxFclIGP.cjs AI (source-diff): Minified default-blocks chunk. ai
source-diff obfuscated-file:dist/BlockNoteSchema-D8TyvlfU.cjs AI (source-diff): Minified rollup chunk, benign build output. ai
source-diff obfuscated-file:dist/TrailingNode-CaT_wbho.cjs AI (source-diff): Minified prosemirror node chunk. ai
source-diff obfuscated-file:dist/blockToNode-CumVjgem.cjs AI (source-diff): Minified build chunk; benign. ai
source-diff obfuscated-file:dist/TrailingNode-n0WdMPUl.cjs AI (source-diff): Minified build chunk; benign. ai
source-diff obfuscated-file:dist/BlockNoteSchema-CCs_V3lo.cjs AI (source-diff): Minified build chunk; readable code, no obfuscation signature. ai
source-diff obfuscated-file:dist/defaultBlocks-Dg9kQWXm.cjs AI (source-diff): Minified build chunk; benign. ai
source-diff obfuscated-file:dist/blocks.cjs AI (source-diff): Minified re-export bundle. ai
source-diff obfuscated-file:dist/en-Cl87Uuyf.cjs AI (source-diff): Locale string data, not obfuscation. ai
source-diff obfuscated-file:dist/comments.cjs AI (source-diff): Minified comments module. ai
source-diff obfuscated-file:dist/blockToNode-w7H99R6p.cjs AI (source-diff): Minified prosemirror block logic. ai
source-diff obfuscated-file:dist/BlockNoteSchema-DjDaA2C3.cjs AI (source-diff): Minified build output; benign editor schema code. ai
source-diff obfuscated-file:dist/blocknote.cjs AI (source-diff): Vite/rollup minified bundle output, not obfuscation; no malicious behavior. ai
source-diff obfuscated-file:dist/locales.cjs AI (source-diff): i18n locale data bundle. ai
source-diff large-new-source-files AI (source-diff): Build output growth in established editor package. ai
source-diff obfuscated-file:dist/extensions-IJK3t0sz.cjs AI (source-diff): Standard minified CJS build output from Vite; source maps included. ai
source-diff obfuscated-file:dist/src-Bcud0PIg.js AI (source-diff): Standard minified ESM build output from Vite; source maps included. ai
source-diff obfuscated-file:dist/src-B6rlChSc.cjs AI (source-diff): Standard minified CJS build output from Vite; source maps included. ai
source-diff obfuscated-file:dist/blocks-Bm6IfL1R.cjs AI (source-diff): Standard minified CJS build output from Vite; source maps included. ai
source-diff obfuscated-file:dist/src-D5R5YzV7.cjs AI (source-diff): Standard Vite-minified CJS bundle output for this build-tool-based package. ai
source-diff obfuscated-file:dist/src-Dvmif2FY.js AI (source-diff): Standard Vite-minified ESM bundle output for this build-tool-based package. ai
source-diff obfuscated-file:dist/extensions-Cutrafjg.cjs AI (source-diff): Standard Vite-minified CJS bundle output for this build-tool-based package. ai
source-diff obfuscated-file:dist/extensions-Cuw3zOdC.cjs AI (source-diff): Standard minified CJS build output from Vite; no obfuscation. ai
source-diff obfuscated-file:dist/src-DK_8q1j5.js AI (source-diff): Standard minified ESM build output from Vite; no obfuscation. ai
source-diff obfuscated-file:dist/src-_83jmA7A.cjs AI (source-diff): Standard minified CJS build output from Vite; no obfuscation. ai
source-diff obfuscated-file:dist/blocks-KyMOxPT3.cjs AI (source-diff): Standard minified CJS build output from Vite; no obfuscation. ai
source-diff obfuscated-file:dist/en-Cj5r8sW_.cjs AI (source-diff): Minified i18n locale data; content is plainly readable UI strings. ai
publish-pattern dormant-publish AI (publish-pattern): Package has 145 versions and 10 approved inbound edges; dormancy signal is likely a registry data anomaly. ai
source-diff obfuscated-file:dist/src-SVFpMAWE.js AI (source-diff): Standard minified ESM build artifact; content is editor core logic. ai
source-diff obfuscated-file:dist/src-DsJ6yzs9.cjs AI (source-diff): Standard minified build artifact; content is editor core logic. ai
source-diff obfuscated-file:dist/extensions-CYsFi5Is.cjs AI (source-diff): Standard minified build artifact; content is editor extension logic. ai
source-diff obfuscated-file:dist/blocks-BFnTypT-.cjs AI (source-diff): Standard minified build output for this editor package; content is readable ProseMirror logic with source maps. ai
phantom-deps phantom-dep:rehype-format AI (phantom-deps): rehype-format is a declared runtime dep used in build/config context; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@tiptap/extension-horizontal-rule AI (phantom-deps): Same as above — tiptap extension re-export pattern; stable false positive. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped package @blocknote/core is a well-known editor, not a typosquat of cors; Levenshtein match is spurious. ai
phantom-deps phantom-dep:@tiptap/extension-paragraph AI (phantom-deps): Tiptap extension deps are re-exported or used indirectly; phantom-dep heuristic is a false positive for this package. ai

Versions (showing 83 of 83)

Version Deps Published
0.52.1 22 / 8
0.52.0 22 / 8
0.51.4 27 / 8
0.51.3 27 / 8
0.51.2 27 / 8
0.51.1 27 / 8
0.51.0 27 / 8
0.50.0 38 / 9
0.49.0 38 / 9
0.48.1 39 / 11
0.48.0 39 / 11
0.47.3 39 / 11
0.47.2 39 / 11
0.47.1 40 / 11
0.47.0 40 / 11
0.46.2 40 / 11
0.46.1 40 / 11
0.46.0 40 / 11
0.45.0 40 / 11
0.44.2 40 / 11
0.44.1 40 / 11
0.44.0 40 / 11
0.43.0 40 / 11
0.42.3 39 / 11
0.42.2 39 / 11
0.42.1 39 / 11
0.42.0 39 / 11
0.22.0 43 / 12
0.17.1 41 / 12
0.17.0 41 / 12
0.16.0 41 / 12
0.15.11 41 / 12
0.15.10 41 / 12
0.15.9 41 / 12
0.15.7 41 / 12
0.15.6 41 / 12
0.15.5 41 / 12
0.15.4 41 / 12
0.15.3 41 / 12
0.15.2 41 / 12
0.15.0 41 / 12
0.14.5 39 / 11
0.14.4 39 / 11
0.14.3 39 / 11
0.14.2 39 / 11
0.14.1 39 / 11
0.14.0 39 / 11
0.13.5 39 / 11
0.13.4 39 / 11
0.13.3 39 / 11
0.13.2 39 / 11
0.13.0 39 / 11
0.12.4 39 / 11
0.12.3 39 / 11
0.12.1 39 / 11
0.12.0 39 / 11
0.11.2 39 / 11
0.11.1 39 / 11
0.11.0 42 / 11
0.10.1 42 / 11
0.10.0 42 / 10
0.9.6 38 / 10
0.9.5 38 / 10
0.9.4 38 / 10
0.9.3 38 / 10
0.9.2 38 / 10
0.9.0 38 / 10
0.8.5 38 / 10
0.8.4 38 / 10
0.8.3 34 / 11
0.8.2 34 / 11
0.8.1 34 / 11
0.8.0 34 / 11
0.7.0 34 / 11
0.6.2 34 / 11
0.6.1 34 / 11
0.5.1 34 / 11
0.5.0 34 / 11
0.3.0 25 / 8
0.2.3 34 / 8
0.2.2 32 / 8
0.2.1 24 / 8
0.2.0 24 / 8

v0.52.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.52.0

7 findings
HIGH New obfuscated file: dist/blocks-BqHv0xhc.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-C5Z4Ag9_.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/extensions-Ghr9QqqR.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src-DTF83Cl9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src-OfbaVbMw.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/y.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.3

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2026-03-25) provenance

This version was published by a different npm account than previous versions on 2026-03-25. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-CCs_V3lo.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-Dg9kQWXm.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-n0WdMPUl.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.2

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2026-03-20) provenance

This version was published by a different npm account than previous versions on 2026-03-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-CCs_V3lo.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-Dg9kQWXm.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-n0WdMPUl.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.1

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2026-03-02) provenance

This version was published by a different npm account than previous versions on 2026-03-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-CwhtPpVC.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-CSB5GiAu.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-DHOdUVUO.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.0

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2026-02-23) provenance

This version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-DT4bdXj5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-D049Pbme.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-tesI8f7N.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.46.2

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2026-01-27) provenance

This version was published by a different npm account than previous versions on 2026-01-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-DmFDeA0n.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-DosClM5E.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-D-CZ76FS.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.46.1

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2026-01-10) provenance

This version was published by a different npm account than previous versions on 2026-01-10. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-qt4Czo0-.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-IsUGVZIq.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-W7GJVng5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.46.0

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2026-01-08) provenance

This version was published by a different npm account than previous versions on 2026-01-08. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-qt4Czo0-.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-IsUGVZIq.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-W7GJVng5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.0

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-12-17) provenance

This version was published by a different npm account than previous versions on 2025-12-17. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-CzZbr4Ed.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-CumVjgem.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-D1cc0lV9.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-DPu6X9ym.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.44.2

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-12-09) provenance

This version was published by a different npm account than previous versions on 2025-12-09. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-CBNkNhkw.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-BX6UxQa8.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-Du4SNHun.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.44.1

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-12-08) provenance

This version was published by a different npm account than previous versions on 2025-12-08. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-B4gm-Qco.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-DLJ4Q1_J.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-CRHrgOnK.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.44.0

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-12-02) provenance

This version was published by a different npm account than previous versions on 2025-12-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-B4gm-Qco.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-DLJ4Q1_J.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-CRHrgOnK.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.43.0

11 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-12-01) provenance

This version was published by a different npm account than previous versions on 2025-12-01. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-D8TyvlfU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/defaultBlocks-BxFclIGP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/TrailingNode-CaT_wbho.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.42.3

9 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-11-19) provenance

This version was published by a different npm account than previous versions on 2025-11-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-DjDaA2C3.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.42.2

9 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-11-19) provenance

This version was published by a different npm account than previous versions on 2025-11-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-DjDaA2C3.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.42.1

9 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-11-18) provenance

This version was published by a different npm account than previous versions on 2025-11-18. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-DjDaA2C3.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.42.0

9 findings
HIGH Publisher changed: matthewlipski → GitHub Actions (on 2025-11-11) provenance

This version was published by a different npm account than previous versions on 2025-11-11. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/blocknote.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/BlockNoteSchema-DjDaA2C3.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blocks.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blockToNode-w7H99R6p.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/comments.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/en-Cl87Uuyf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: matthewlipski → yousefed (on 2024-10-18, known maintainer) provenance

This version was published by a different npm account (yousefed) than the most recent previously approved version (matthewlipski) on 2024-10-18, but yousefed is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yousefed → matthewlipski (on 2024-08-17, known maintainer) provenance

This version was published by a different npm account (matthewlipski) than the most recent previously approved version (yousefed) on 2024-08-17, but matthewlipski is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.15.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yousefed → matthewlipski (on 2024-08-08, known maintainer) provenance

This version was published by a different npm account (matthewlipski) than the most recent previously approved version (yousefed) on 2024-08-08, but matthewlipski is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.15.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: matthewlipski → yousefed (on 2024-07-18, known maintainer) provenance

This version was published by a different npm account (yousefed) than the most recent previously approved version (matthewlipski) on 2024-07-18, but yousefed is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.15.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: matthewlipski → yousefed (on 2024-07-03, known maintainer) provenance

This version was published by a different npm account (yousefed) than the most recent previously approved version (matthewlipski) on 2024-07-03, but yousefed is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.14.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: matthewlipski → yousefed (on 2024-06-02, known maintainer) provenance

This version was published by a different npm account (yousefed) than the most recent previously approved version (matthewlipski) on 2024-06-02, but yousefed is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.13.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.