@camunda/linting
Linting for Camunda
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Official Camunda linting lib; 38-byte index.js is a normal ESM barrel re-export, publisher is legit Camunda maintainer barmac. | ai | |
| dependencies | unvetted-dep:modeler-moddle | AI (dependencies): modeler-moddle is a Camunda ecosystem moddle extension; stable dependency for this package. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 3.52.0 | 12 / 20 | |
| 3.37.0 | 12 / 21 | |
| 3.36.1 | 12 / 21 | |
| 3.36.0 | 12 / 21 | |
| 3.35.0 | 12 / 21 | |
| 3.34.0 | 12 / 21 | |
| 3.33.0 | 12 / 21 | |
| 3.32.1 | 12 / 21 | |
| 3.32.0 | 12 / 21 | |
| 3.31.0 | 12 / 21 | |
| 3.30.0 | 12 / 21 | |
| 3.29.1 | 12 / 21 | |
| 3.29.0 | 12 / 21 | |
| 3.28.0 | 12 / 21 | |
| 3.27.2 | 12 / 21 | |
| 3.27.1 | 12 / 21 | |
| 3.27.0 | 12 / 21 | |
| 3.26.1 | 12 / 21 | |
| 3.26.0 | 12 / 21 | |
| 3.25.0 | 12 / 21 | |
| 3.24.0 | 12 / 21 | |
| 3.23.0 | 12 / 21 | |
| 3.22.0 | 12 / 21 | |
| 3.21.1 | 12 / 21 | |
| 3.21.0 | 12 / 21 | |
| 3.20.0 | 12 / 21 | |
| 3.19.0 | 12 / 21 |
v3.52.0
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): SPAM-FLAGGED publisher with 20 rejections; empty entry point indicates account compromise or malicious intent.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: barinali. • [S_EMPTY_MAIN] Entry point (index.js) is 38 bytes — effectively empty.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.37.0
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): SPAM-FLAGGED publisher with 20 rejections; empty entry point indicates account compromise or malicious intent.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jarekdanielak, simon-steinruecken-camunda. • [S_EMPTY_MAIN] Entry point (index.js) is 38 bytes — effectively empty.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.36.1
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): SPAM-FLAGGED publisher with 20 rejections; empty entry point indicates account compromise or malicious intent.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jarekdanielak, simon-steinruecken-camunda. • [S_EMPTY_MAIN] Entry point (index.js) is 38 bytes — effectively empty.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.36.0
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): SPAM-FLAGGED publisher with 20 rejections; empty entry point indicates account compromise or malicious intent.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jarekdanielak, simon-steinruecken-camunda. • [S_EMPTY_MAIN] Entry point (index.js) is 38 bytes — effectively empty.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.35.0
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): SPAM-FLAGGED publisher with 20 rejections; empty entry point indicates account compromise or malicious intent.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jarekdanielak. • [S_EMPTY_MAIN] Entry point (index.js) is 38 bytes — effectively empty.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.0
3 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): SPAM-FLAGGED publisher with 20 rejections; empty entry point indicates account compromise or malicious intent.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jarekdanielak. • [S_EMPTY_MAIN] Entry point (index.js) is 38 bytes — effectively empty.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (nikku) on 2025-03-03, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.33.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (nikku) on 2025-02-24, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.32.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (barmac) on 2025-02-20, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.32.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (barmac) on 2025-02-20, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.29.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (philippfromme) on 2024-11-25, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.29.0
2 findingsThis version was published by a different npm account (misiekhardcore) than the most recent previously approved version (philippfromme) on 2024-11-18. It has since remained available on npm for 606 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.28.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (nikku) on 2024-10-24, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.27.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (nikku) on 2024-10-11, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.27.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (philippfromme) on 2024-09-19, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.26.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (nikku) on 2024-09-09, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.26.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (nikku) on 2024-08-27, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.25.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (philippfromme) on 2024-08-22, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.24.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (barmac) on 2024-08-01, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.21.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (marstamm) on 2024-06-17, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.20.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marstamm) than the most recent previously approved version (philippfromme) on 2024-05-24, but marstamm is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.