@decaf-ts/logging
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Minor metadata gap, no behavioral change vs prior approved version. | ai | |
| source-diff | obfuscated-file:lib/types.cjs | AI (source-diff): Bundled TS-compiled output with sourcemap comment, not obfuscated. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Explained by added dual cjs/esm winston build outputs, not injected payload. | ai | |
| source-diff | obfuscated-file:lib/esm/winston/winston.js | AI (source-diff): ESM build artifact, readable winston wrapper. | ai | |
| source-diff | obfuscated-file:lib/esm/types.js | AI (source-diff): ESM build artifact with sourcemap, not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/winston/winston.cjs | AI (source-diff): Compiled CJS wrapper around winston, readable code. | ai | |
| source-diff | obfuscated-file:dist/logging.cjs | AI (source-diff): UMD/rollup bundle output, not obfuscation; long-lines are minification artifact. | ai | |
| source-diff | obfuscated-file:dist/esm/logging.js | AI (source-diff): Webpack-bundled dist output, not obfuscation; matches package build process. | ai | |
| source-diff | obfuscated-file:dist/logging.js | AI (source-diff): dist/logging.js is standard minified ESM bundle output; content is clearly logging library code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:lib/esm/time.js | AI (source-diff): Standard tsc output with inline sourcemaps; long lines from base64 sourcemap, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/filters/LogFilter.cjs | AI (source-diff): Standard tsc output with inline sourcemaps; long lines from base64 sourcemap, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/filters/PatternFilter.cjs | AI (source-diff): Standard tsc output with inline sourcemaps; long lines from base64 sourcemap, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/time.cjs | AI (source-diff): Standard tsc output with inline sourcemaps; long lines from base64 sourcemap, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/esm/filters/LogFilter.js | AI (source-diff): Standard tsc output with inline sourcemaps; long lines from base64 sourcemap, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/esm/filters/PatternFilter.js | AI (source-diff): Standard tsc output with inline sourcemaps; long lines from base64 sourcemap, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/esm/text.js | AI (source-diff): Readable ESM compiled output with JSDoc; false positive on long-line heuristic. | ai | |
| source-diff | obfuscated-file:lib/esm/environment.js | AI (source-diff): Readable ESM compiled output with JSDoc; false positive on long-line heuristic. | ai | |
| source-diff | obfuscated-file:lib/text.cjs | AI (source-diff): Readable TypeScript-compiled CJS output; false positive on long-line heuristic. | ai | |
| source-diff | obfuscated-file:lib/environment.cjs | AI (source-diff): Readable TypeScript-compiled CJS output with JSDoc; long lines from bundled source map or type annotations, not obfuscation. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() used inside a Proxy get() trap — standard JS Proxy pattern, not obfuscation. | ai |
Versions (showing 51 of 82)
| Version | Deps | Published |
|---|---|---|
| 0.23.6 | 2 / 2 | |
| 0.23.5 | 2 / 2 | |
| 0.23.4 | 2 / 2 | |
| 0.23.3 | 2 / 2 | |
| 0.23.2 | 2 / 2 | |
| 0.23.1 | 2 / 2 | |
| 0.23.0 | 2 / 2 | |
| 0.22.1 | 2 / 2 | |
| 0.22.0 | 2 / 2 | |
| 0.21.1 | 2 / 2 | |
| 0.21.0 | 2 / 2 | |
| 0.20.0 | 2 / 2 | |
| 0.19.0 | 2 / 2 | |
| 0.18.0 | 2 / 2 | |
| 0.17.0 | 2 / 2 | |
| 0.16.0 | 2 / 2 | |
| 0.15.0 | 2 / 2 | |
| 0.14.0 | 2 / 2 | |
| 0.13.0 | 2 / 2 | |
| 0.12.6 | 2 / 2 | |
| 0.12.5 | 2 / 2 | |
| 0.12.4 | 2 / 2 | |
| 0.12.3 | 2 / 2 | |
| 0.12.2 | 2 / 2 | |
| 0.12.1 | 2 / 2 | |
| 0.12.0 | 2 / 2 | |
| 0.9.2 | 0 / 2 | |
| 0.9.1 | 1 / 27 | |
| 0.9.0 | 1 / 27 | |
| 0.8.1 | 1 / 27 | |
| 0.8.0 | 1 / 27 | |
| 0.7.0 | 1 / 27 | |
| 0.6.0 | 1 / 27 | |
| 0.5.0 | 1 / 27 | |
| 0.4.0 | 1 / 27 | |
| 0.3.28 | 1 / 27 | |
| 0.3.27 | 1 / 27 | |
| 0.3.26 | 1 / 27 | |
| 0.3.25 | 1 / 27 | |
| 0.3.24 | 1 / 32 | |
| 0.3.23 | 1 / 32 | |
| 0.3.22 | 1 / 32 | |
| 0.3.21 | 1 / 32 | |
| 0.3.20 | 1 / 32 | |
| 0.3.19 | 1 / 32 | |
| 0.3.18 | 1 / 32 | |
| 0.3.17 | 1 / 32 | |
| 0.3.16 | 1 / 32 | |
| 0.3.15 | 1 / 32 | |
| 0.3.14 | 1 / 32 | |
| 0.3.13 | 1 / 32 |
v0.23.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.19.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tvenceslau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.