@bpmn-io/feel-analyzer
Static FEEL expression analyzer
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer matches known bpmn-io org contributor pattern, not a compromise indicator. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Known maintainer reshuffle within bpmn-io org, not a takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @lezer/common is a standard parser dep fitting the package's purpose. | ai | |
| dependencies | unvetted-dep:@bpmn-io/lezer-feel | AI (dependencies): Sibling first-party bpmn-io dependency, expected for a FEEL analyzer. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established bpmn-io/Camunda package; spam-publisher flag is a false positive here given verified known-maintainer manual publish. | ai | |
| provenance | no-provenance | AI (provenance): bpmn-io org packages commonly lack Sigstore provenance; not a meaningful risk signal here. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 0.5.0 | 2 / 14 | |
| 0.4.0 | 1 / 14 | |
| 0.3.0 | 1 / 14 | |
| 0.1.0 | 1 / 14 |
v0.5.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (jarekdanielak) on 2026-07-08, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.0
3 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Publisher jarekdanielak is SPAM-FLAGGED; this disqualifier generalizes to all versions published by this account.) Matched 1 signal(s), weighted score 3: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: bpmn-io-admin, barinali, jarekdanielak.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (simon-steinruecken-camunda) on 2026-07-01, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (simon-steinruecken-camunda) on 2026-05-19, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.