← Home

@colijnit/sharedcomponents

This library was generated with [Angular CLI](https://github.com/angular/angular-cli) version 13.1.0.

38
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

patrickvkeulenralf.eversendaan.vdjelskedeyan_colijnityury.sjilliscitjkruijtgoran_silic_colijn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:358.645812766f7a400d0d38.js AI (source-diff): Webpack-bundled vendor chunk, not obfuscation; consistent with library's own build output. ai
source-diff source-size-tripled AI (source-diff): Bundled dictionaries/sourcemaps inflate size; consistent with legitimate build. ai
source-diff obfuscated-file:esm2015/lib/components/activity-list-header/activity-list-header.component.js AI (source-diff): Angular AOT component output, long template literal not real obfuscation. ai
source-diff large-new-source-files AI (source-diff): Normal ng-packagr build output growth, not injected code. ai
source-diff net-exec-file:browser/chunk-KTNFH73E.js AI (source-diff): Bundled build output (core-js/polyfills), not a dropper; standard bundler artifact. ai
source-diff net-exec-file:browser/main-AKBSJVK6.js AI (source-diff): Same bundled file as above, false positive pattern for this Angular lib. ai
source-diff obfuscated-file:browser/main-AKBSJVK6.js AI (source-diff): Minified bundled JS (zlib/core-js), long lines are build output not obfuscation. ai
source-diff obfuscated-file:977.bd6291f9ee6f6ddf91f1.js AI (source-diff): Webpack-bundled chunk, standard minified library code. ai
source-diff obfuscated-file:main.19bc84d64838d669680c.js AI (source-diff): Webpack bundle output for Angular lib; minified, not obfuscated malware. ai
source-diff net-exec-file:main.19bc84d64838d669680c.js AI (source-diff): Standard bundled vendor code (AjaxService/connector), no exfil to unrelated host. ai
source-diff obfuscated-file:693.acbc6febd2976ef6a8ac.js AI (source-diff): Bundled vendor utility (raf/color) chunk, not obfuscation. ai
source-diff net-exec-file:693.acbc6febd2976ef6a8ac.js AI (source-diff): Bundled vendor utility chunk; pattern match false positive. ai
source-diff obfuscated-file:esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js AI (source-diff): Long line is Angular ESM build formatting, not obfuscation; sample shows plain readable code. ai
source-diff obfuscated-file:main.cd71aae77dce017e8a8c.js AI (source-diff): Webpack-bundled Angular main bundle, not obfuscation. ai
source-diff obfuscated-file:13.15fdfa0d6e926c28e3f2.js AI (source-diff): Webpack-bundled output, not true obfuscation. ai
source-diff net-exec-file:13.15fdfa0d6e926c28e3f2.js AI (source-diff): Generic bundled polyfill code, no concrete malicious behavior. ai
source-diff net-exec-file:main.cd71aae77dce017e8a8c.js AI (source-diff): Bundled app code; no exfil/dropper behavior evidenced. ai
source-diff obfuscated-file:esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js AI (source-diff): Sample is readable Angular source, not obfuscated; long-line artifact of build output. ai
source-diff obfuscated-file:esm2015/lib/components/send-method-dialog/components/pdf-preview/pdf-preview.component.js AI (source-diff): Long line is a template literal in normal Angular component source, not obfuscation. ai
source-diff obfuscated-file:browser/main-7K2JRI54.js AI (source-diff): Bundled minified build output (zlib/polyfill libs), not true obfuscation. ai
source-diff net-exec-file:browser/main-7K2JRI54.js AI (source-diff): Bundled build output; same false-positive pattern as sibling chunk. ai
source-diff net-exec-file:browser/chunk-5PPHQWL6.js AI (source-diff): Bundled polyfill/core-js chunk; no malicious network+exec behavior found. ai
publish-pattern new-deps-added AI (publish-pattern): Fingerprintjs is a legitimate, declared dependency consistent with package function. ai
source-diff obfuscated-file:fesm2022/colijnit-sharedcomponents.mjs AI (source-diff): Standard Angular fesm2022 bundle output, not obfuscation. ai
provenance publisher-changed AI (provenance): jilliscit is an established publisher (41 approved, 0 rejected) within the @colijnit org; transition appears legitimate. ai
phantom-deps phantom-dep:xlsx AI (phantom-deps): xlsx is a peerDependency; not directly imported by the library itself is expected. ai
phantom-deps phantom-dep:hammerjs AI (phantom-deps): hammerjs is an Angular peer dep loaded by convention; phantom finding is a stable false positive. ai
phantom-deps phantom-dep:@types/jspdf AI (phantom-deps): Type-only package; not directly imported at runtime is expected. ai
phantom-deps phantom-dep:@types/three AI (phantom-deps): Type-only package; not directly imported at runtime is expected. ai
phantom-deps phantom-dep:@types/hammerjs AI (phantom-deps): Type-only package; not directly imported at runtime is expected. ai
phantom-deps phantom-dep:jspdf-autotable AI (phantom-deps): Config-referenced peer dep; phantom finding is a stable false positive for this library. ai
phantom-deps phantom-dep:@angular/compiler AI (phantom-deps): Angular compiler is loaded by framework convention; not directly imported is expected. ai
phantom-deps phantom-dep:@tweenjs/tween.js AI (phantom-deps): Config-referenced optional dep; phantom finding is a stable false positive for this library. ai
provenance no-provenance AI (provenance): Established org package with 233 versions; lack of Sigstore provenance is consistent across all prior releases. ai
phantom-deps phantom-dep:three AI (phantom-deps): three is a peer/optional dep referenced in config; not directly imported is expected for this library. ai
phantom-deps phantom-dep:chart.js AI (phantom-deps): Config-referenced dependency; stable for this package. ai
phantom-deps phantom-dep:@fingerprintjs/fingerprintjs AI (phantom-deps): Config-referenced dependency; stable for this package. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): Known implicit dependency; stable pattern for TypeScript libraries. ai

Versions (showing 38 of 38)

Version Deps Published
300.1.1 3 / 0
300.1.0 3 / 0
262.1.14 3 / 0
262.1.11 3 / 0
262.1.8 3 / 0
262.1.5 3 / 0
262.1.3 3 / 0
262.1.0 3 / 0
261.20.11 3 / 0
261.20.10 3 / 0
261.20.7 3 / 0
261.20.5 3 / 0
261.20.2 3 / 0
261.20.1 3 / 0
261.20.0 3 / 0
261.1.2 37 / 16
261.1.1 2 / 0
261.1.0 2 / 0
260.1.19 2 / 0
260.1.18 2 / 0
260.1.17 2 / 0
260.1.16 2 / 0
260.1.15 2 / 0
260.1.14 2 / 0
260.1.13 2 / 0
260.1.10 2 / 0
260.1.9 2 / 0
260.1.8 2 / 0
260.1.7 2 / 0
260.1.5 2 / 0
260.1.4 2 / 0
260.1.3 2 / 0
259.1.24 2 / 0
259.1.23 2 / 0
259.1.22 2 / 0
259.1.21 2 / 0
259.1.20 2 / 0
258.1.18 2 / 0

v300.1.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ralf.eversen → deyan_colijnit (on 2026-07-22, known maintainer) provenance

This version was published by a different npm account (deyan_colijnit) than the most recent previously approved version (ralf.eversen) on 2026-07-22, but deyan_colijnit is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v300.1.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jkruijt → ralf.eversen (on 2026-07-13, known maintainer) provenance

This version was published by a different npm account (ralf.eversen) than the most recent previously approved version (jkruijt) on 2026-07-13, but ralf.eversen is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v262.1.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: patrickvkeulen → ralf.eversen (on 2026-04-14, known maintainer) provenance

This version was published by a different npm account (ralf.eversen) than the most recent previously approved version (patrickvkeulen) on 2026-04-14, but ralf.eversen is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v261.20.2

2 findings
HIGH New obfuscated file: fesm2022/colijnit-sharedcomponents.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v261.20.1

5 findings
HIGH New file with network + code execution: browser/chunk-KTNFH73E.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: browser/main-AKBSJVK6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: browser/main-AKBSJVK6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: fesm2022/colijnit-sharedcomponents.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v261.20.0

3 findings
HIGH New obfuscated file: fesm2022/colijnit-sharedcomponents.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jkruijt → patrickvkeulen (on 2026-01-23, known maintainer) provenance

This version was published by a different npm account (patrickvkeulen) than the most recent previously approved version (jkruijt) on 2026-01-23, but patrickvkeulen is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v261.1.1

10 findings
HIGH New obfuscated file: 358.645812766f7a400d0d38.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: 693.acbc6febd2976ef6a8ac.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: 693.acbc6febd2976ef6a8ac.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: 977.bd6291f9ee6f6ddf91f1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: main.19bc84d64838d669680c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: main.19bc84d64838d669680c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → jkruijt (on 2026-01-14, known maintainer) provenance

This version was published by a different npm account (jkruijt) than the most recent previously approved version (daan.vdj) on 2026-01-14, but jkruijt is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v261.1.0

4 findings
HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → ralf.eversen (on 2026-01-13, known maintainer) provenance

This version was published by a different npm account (ralf.eversen) than the most recent previously approved version (daan.vdj) on 2026-01-13, but ralf.eversen is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v260.1.19

30 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jkruijt.

HIGH New obfuscated file: esm2015/lib/components/activity-list-header/activity-list-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/activity-list/activity-list.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/modify-task-form/components/activity-summary-block/activity-summary-block.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/additional-file-button/additional-file-button.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-base-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-event.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-events.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-half-hour-cell.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-hour-view-labels.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-hour-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-month-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-select-event.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-week-select-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-week-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/directives/align-with.directive.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/stock/components/allocation-stock-history/allocation-stock-history.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/app-file-dropzone/app-file-dropzone.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/utils/array-utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/activity-overview-component/components/base-activity-overview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/modify-task-form/components/base-activity-summary.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/files-upload/components/base-file-upload.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/open-activity-list/components/base-open-activity-list.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/utils/browser-utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-all-years.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.18

33 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jkruijt.

HIGH New obfuscated file: 358.645812766f7a400d0d38.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: 693.acbc6febd2976ef6a8ac.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: 693.acbc6febd2976ef6a8ac.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: 977.bd6291f9ee6f6ddf91f1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: esm2015/lib/components/activity-list-header/activity-list-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/activity-list/activity-list.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/modify-task-form/components/activity-summary-block/activity-summary-block.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/additional-file-button/additional-file-button.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-base-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-event.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-events.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-half-hour-cell.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-hour-view-labels.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-hour-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-month-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-select-event.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-week-select-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-week-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/directives/align-with.directive.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/stock/components/allocation-stock-history/allocation-stock-history.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/app-file-dropzone/app-file-dropzone.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/utils/array-utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/activity-overview-component/components/base-activity-overview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/modify-task-form/components/base-activity-summary.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/files-upload/components/base-file-upload.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/open-activity-list/components/base-open-activity-list.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/utils/browser-utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-all-years.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.17

30 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jkruijt.

HIGH New obfuscated file: esm2015/lib/components/activity-list-header/activity-list-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/activity-list/activity-list.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/modify-task-form/components/activity-summary-block/activity-summary-block.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/additional-file-button/additional-file-button.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-base-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-event.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-events.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-half-hour-cell.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-hour-view-labels.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-hour-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-month-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-select-event.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-week-select-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/agenda/agenda-week-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/directives/align-with.directive.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/stock/components/allocation-stock-history/allocation-stock-history.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/app-file-dropzone/app-file-dropzone.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/utils/array-utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/activity-overview-component/components/base-activity-overview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/modify-task-form/components/base-activity-summary.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/files-upload/components/base-file-upload.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/open-activity-list/components/base-open-activity-list.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/utils/browser-utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-all-years.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-header.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/date-planning/component/calendar/calendar-view.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.16

3 findings
HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.15

4 findings
HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → goran_silic_colijn (on 2025-12-31, known maintainer) provenance

This version was published by a different npm account (goran_silic_colijn) than the most recent previously approved version (daan.vdj) on 2025-12-31, but goran_silic_colijn is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v260.1.14

4 findings
HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → elske (on 2025-12-29, known maintainer) provenance

This version was published by a different npm account (elske) than the most recent previously approved version (daan.vdj) on 2025-12-29, but elske is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v260.1.13

4 findings
HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → goran_silic_colijn (on 2025-12-25, known maintainer) provenance

This version was published by a different npm account (goran_silic_colijn) than the most recent previously approved version (daan.vdj) on 2025-12-25, but goran_silic_colijn is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v260.1.10

3 findings
HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.9

3 findings
HIGH New obfuscated file: esm2015/lib/components/form-builder/form-builder-user-form/form-builder-question.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.8

2 findings
HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.7

2 findings
HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/send-method-combine-print-email/send-method-combine-print-email.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v260.1.5

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: elske → daan.vdj (on 2025-11-11, known maintainer) provenance

This version was published by a different npm account (daan.vdj) than the most recent previously approved version (elske) on 2025-11-11, but daan.vdj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v260.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v260.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v259.1.24

3 findings
HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/pdf-preview/pdf-preview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → goran_silic_colijn (on 2025-12-31, known maintainer) provenance

This version was published by a different npm account (goran_silic_colijn) than the most recent previously approved version (daan.vdj) on 2025-12-31, but goran_silic_colijn is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v259.1.23

3 findings
HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/pdf-preview/pdf-preview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → elske (on 2025-12-29, known maintainer) provenance

This version was published by a different npm account (elske) than the most recent previously approved version (daan.vdj) on 2025-12-29, but elske is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v259.1.22

3 findings
HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/pdf-preview/pdf-preview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daan.vdj → elske (on 2025-12-09, known maintainer) provenance

This version was published by a different npm account (elske) than the most recent previously approved version (daan.vdj) on 2025-12-09, but elske is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v259.1.21

6 findings
HIGH New obfuscated file: 13.15fdfa0d6e926c28e3f2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: 13.15fdfa0d6e926c28e3f2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: main.cd71aae77dce017e8a8c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: main.cd71aae77dce017e8a8c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/pdf-preview/pdf-preview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v259.1.20

2 findings
HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/pdf-preview/pdf-preview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v258.1.18

2 findings
HIGH New obfuscated file: esm2015/lib/components/send-method-dialog/components/pdf-preview/pdf-preview.component.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.