@contrail/sdk
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@nestjs/common | AI (phantom-deps): Likely used via TS types/decorators not caught by import scan; established dep. | ai | |
| provenance | publisher-changed | AI (provenance): Move to GitHub Actions CI publishing for this org's SDK; stable across future versions. | ai | |
| dependencies | unvetted-dep:@contrail/cache | AI (dependencies): First-party @contrail scoped sibling package, same publisher/monorepo. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are same-org first-party packages, not third-party additions. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are org colleagues; publisher matched known prior maintainer. | ai | |
| source-diff | obfuscated-file:docs/assets/main.js | AI (source-diff): Typedoc-generated docs bundle (lunr search), not injected obfuscation. | ai | |
| source-diff | obfuscated-file:docs/assets/search.js | AI (source-diff): Typedoc-generated search index/bundle, matches generate-docs script. | ai | |
| phantom-deps | phantom-dep:@contrail/util | AI (phantom-deps): Same-org dependency; likely used transitively or in config rather than direct import. | ai | |
| phantom-deps | phantom-dep:es6-promisify | AI (phantom-deps): Declared in package.json dependencies; likely used indirectly or in config files, stable false positive for this package. | ai |
Versions (showing 51 of 255)
| Version | Deps | Published |
|---|---|---|
| 1.5.18 | 10 / 12 | |
| 1.5.17 | 10 / 12 | |
| 1.5.16 | 10 / 12 | |
| 1.5.15 | 10 / 12 | |
| 1.5.14 | 10 / 12 | |
| 1.5.13 | 10 / 12 | |
| 1.5.12 | 10 / 12 | |
| 1.5.11 | 10 / 12 | |
| 1.5.10 | 10 / 12 | |
| 1.5.9 | 10 / 12 | |
| 1.5.8 | 10 / 12 | |
| 1.5.7 | 10 / 12 | |
| 1.5.5 | 10 / 12 | |
| 1.5.4 | 10 / 12 | |
| 1.5.3 | 10 / 12 | |
| 1.5.2 | 10 / 12 | |
| 1.5.1 | 10 / 12 | |
| 1.5.0 | 10 / 12 | |
| 1.4.19 | 10 / 12 | |
| 1.4.18 | 10 / 12 | |
| 1.4.17 | 10 / 12 | |
| 1.4.16 | 10 / 12 | |
| 1.4.15 | 10 / 10 | |
| 1.4.14 | 10 / 10 | |
| 1.4.13 | 10 / 10 | |
| 1.4.12 | 10 / 10 | |
| 1.4.11 | 10 / 10 | |
| 1.4.10 | 10 / 10 | |
| 1.4.9 | 10 / 10 | |
| 1.4.8 | 10 / 10 | |
| 1.4.7 | 9 / 10 | |
| 1.4.6 | 9 / 10 | |
| 1.4.5 | 9 / 10 | |
| 1.4.4 | 9 / 10 | |
| 1.4.3 | 9 / 10 | |
| 1.4.2 | 9 / 10 | |
| 1.4.1 | 9 / 10 | |
| 1.4.0 | 9 / 10 | |
| 1.3.14 | 9 / 10 | |
| 1.3.13 | 9 / 10 | |
| 1.3.12 | 9 / 10 | |
| 1.3.11 | 9 / 10 | |
| 1.3.10 | 9 / 10 | |
| 1.3.9 | 9 / 10 | |
| 1.3.8 | 9 / 10 | |
| 1.3.7 | 9 / 10 | |
| 1.3.6 | 9 / 10 | |
| 1.3.5 | 9 / 10 | |
| 1.3.3 | 9 / 9 | |
| 1.3.2 | 9 / 9 | |
| 1.3.1 | 9 / 8 |
v1.5.18
2 findingsThis version was published by a different npm account than previous versions on 2026-06-11. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.16
2 findingsThis version was published by a different npm account than previous versions on 2026-05-12. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (zileeva) on 2026-05-09, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.13
2 findingsThis version was published by a different npm account than previous versions on 2026-05-07. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.12
2 findingsThis version was published by a different npm account than previous versions on 2026-05-04. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zileeva) than the most recent previously approved version (zachsibert_vibeiq) on 2026-05-04, but zileeva is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adamvibeiq) than the most recent previously approved version (mattvitello) on 2025-10-08, but adamvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (mattvitello) on 2025-09-10, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (brian.lindauer) than the most recent previously approved version (btosadoprater) on 2025-08-02, but brian.lindauer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (mattvitello) on 2025-07-30, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adamvibeiq) than the most recent previously approved version (mattvitello) on 2025-07-18, but adamvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adamvibeiq) than the most recent previously approved version (mattvitello) on 2025-06-27, but adamvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13
2 findingsThis version was published by a different npm account than previous versions on 2025-03-10. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (chris_vibeiq) on 2025-02-12, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (chris_vibeiq) on 2025-01-30, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (chris_vibeiq) on 2025-01-27, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (chris_vibeiq) on 2025-01-02, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (chris_vibeiq) on 2024-12-20, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chris_vibeiq) than the most recent previously approved version (prashantvibeiq) on 2024-11-12, but chris_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (prashantvibeiq) than the most recent previously approved version (btosadoprater) on 2024-11-06, but prashantvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (prashantvibeiq) than the most recent previously approved version (btosadoprater) on 2024-11-05, but prashantvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (chris_vibeiq) on 2024-10-15, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chris_vibeiq) than the most recent previously approved version (mattvitello) on 2024-10-04, but chris_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (mattvitello) on 2024-09-14, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.14
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (mattvitello) on 2024-08-23, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (kamalvibeiq) on 2024-07-23, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (mattvitello) on 2024-04-15, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (mattvitello) on 2024-04-09, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (btosadoprater) on 2024-02-12, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mattvitello) than the most recent previously approved version (btosadoprater) on 2024-02-05, but mattvitello is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (kamalvibeiq) on 2024-01-12, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.