@decocms/bindings
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Cosmetic; not indicative of malware for this established package. | ai | |
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer; env change explains missing gitHead, benign. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established scoped lib with 1.9k downloads; missing metadata is not spam here. | ai | |
| source-diff | net-exec-file:dist/browser/chunk-6QEXJ7XW.js | AI (source-diff): Bundled MCP SDK transport code, not a dropper; network+eval pattern is normal for MCP client bundles. | ai | |
| source-diff | net-exec-file:dist/node/chunk-QP7AQCEP.js | AI (source-diff): Bundled MCP SDK transport code, not a dropper; network+eval pattern is normal for MCP client bundles. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase from bundling new MCP SDK dependency, matches added deps. | ai | |
| provenance | no-provenance | AI (provenance): Absence of provenance is common; no other risk signals present to elevate this. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 1.4.12 | 4 / 0 | |
| 1.4.11 | 4 / 0 | |
| 1.4.10 | 4 / 0 | |
| 1.4.9 | 6 / 2 | |
| 1.4.8 | 6 / 2 | |
| 1.4.7 | 6 / 2 | |
| 1.4.6 | 6 / 2 | |
| 1.4.5 | 5 / 2 | |
| 1.4.4 | 5 / 2 | |
| 1.4.3 | 5 / 2 | |
| 1.4.2 | 5 / 2 | |
| 1.4.1 | 5 / 2 | |
| 1.4.0 | 5 / 2 | |
| 1.3.4 | 5 / 2 | |
| 1.3.3 | 5 / 2 | |
| 1.3.2 | 5 / 2 | |
| 1.3.1 | 5 / 2 | |
| 1.3.0 | 5 / 2 | |
| 1.2.1 | 5 / 2 | |
| 1.2.0 | 5 / 2 | |
| 1.1.3 | 5 / 2 | |
| 1.1.2 | 5 / 2 | |
| 1.1.1 | 5 / 0 | |
| 1.1.0 | 5 / 0 | |
| 1.0.9 | 5 / 0 | |
| 1.0.8 | 3 / 0 | |
| 1.0.7 | 3 / 0 | |
| 1.0.6 | 3 / 0 | |
| 1.0.5 | 3 / 0 | |
| 1.0.4 | 3 / 0 | |
| 1.0.3 | 3 / 0 | |
| 1.0.2 | 3 / 0 | |
| 1.0.1 | 3 / 0 | |
| 1.0.0 | 4 / 1 | |
| 0.2.5 | 4 / 3 | |
| 0.2.4 | 4 / 3 | |
| 0.2.3 | 5 / 4 | |
| 0.2.2 | 5 / 4 | |
| 0.2.1 | 3 / 3 | |
| 0.2.0 | 3 / 3 | |
| 0.1.6 | 3 / 3 | |
| 0.1.5 | 3 / 3 | |
| 0.1.4 | 3 / 3 | |
| 0.1.3 | 3 / 3 | |
| 0.1.2 | 3 / 3 | |
| 0.1.1 | 3 / 3 | |
| 0.1.0 | 3 / 3 |
v1.4.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (gimenes-decocx) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.2.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (gimenes-decocx) on 2026-02-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.2.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-28, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.3
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-25, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.2
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-25, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-23, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-23, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.9
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-20, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.8
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-08, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.7
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-06, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.6
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-06, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.5
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-06, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.4
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-05, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.3
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-31, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.2
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-30, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-30, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-01, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.2.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.