← Home

@decocms/bindings

47
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

camudonicacioliveiragimenes-decocxcrazydeviljonasjesusfirstdoitvinventura

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata no-description AI (npm-metadata): Cosmetic; not indicative of malware for this established package. ai
provenance missing-githead AI (provenance): Manual publish by known maintainer; env change explains missing gitHead, benign. ai
bogus-package bogus-package AI (bogus-package): Established scoped lib with 1.9k downloads; missing metadata is not spam here. ai
source-diff net-exec-file:dist/browser/chunk-6QEXJ7XW.js AI (source-diff): Bundled MCP SDK transport code, not a dropper; network+eval pattern is normal for MCP client bundles. ai
source-diff net-exec-file:dist/node/chunk-QP7AQCEP.js AI (source-diff): Bundled MCP SDK transport code, not a dropper; network+eval pattern is normal for MCP client bundles. ai
source-diff source-size-tripled AI (source-diff): Size increase from bundling new MCP SDK dependency, matches added deps. ai
provenance no-provenance AI (provenance): Absence of provenance is common; no other risk signals present to elevate this. ai

Versions (showing 47 of 47)

Version Deps Published
1.4.12 4 / 0
1.4.11 4 / 0
1.4.10 4 / 0
1.4.9 6 / 2
1.4.8 6 / 2
1.4.7 6 / 2
1.4.6 6 / 2
1.4.5 5 / 2
1.4.4 5 / 2
1.4.3 5 / 2
1.4.2 5 / 2
1.4.1 5 / 2
1.4.0 5 / 2
1.3.4 5 / 2
1.3.3 5 / 2
1.3.2 5 / 2
1.3.1 5 / 2
1.3.0 5 / 2
1.2.1 5 / 2
1.2.0 5 / 2
1.1.3 5 / 2
1.1.2 5 / 2
1.1.1 5 / 0
1.1.0 5 / 0
1.0.9 5 / 0
1.0.8 3 / 0
1.0.7 3 / 0
1.0.6 3 / 0
1.0.5 3 / 0
1.0.4 3 / 0
1.0.3 3 / 0
1.0.2 3 / 0
1.0.1 3 / 0
1.0.0 4 / 1
0.2.5 4 / 3
0.2.4 4 / 3
0.2.3 5 / 4
0.2.2 5 / 4
0.2.1 3 / 3
0.2.0 3 / 3
0.1.6 3 / 3
0.1.5 3 / 3
0.1.4 3 / 3
0.1.3 3 / 3
0.1.2 3 / 3
0.1.1 3 / 3
0.1.0 3 / 3

v1.4.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: gimenes-decocx → GitHub Actions (on 2026-02-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (gimenes-decocx) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.2.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: gimenes-decocx → GitHub Actions (on 2026-02-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (gimenes-decocx) on 2026-02-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.2.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-28, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-28, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.3

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-25, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-25, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.2

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-25, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-25, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.1

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-23, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-23, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-23, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-23, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.9

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-20, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-20, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.8

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-08, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-08, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.7

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-06, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-06, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.6

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-06, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-06, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.5

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-06, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-06, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.4

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2026-01-05, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2026-01-05, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.3

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2025-12-31, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-31, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.2

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2025-12-30, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-30, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.1

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2025-12-30, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-30, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: camudo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gimenes-decocx → camudo (on 2025-12-01, known maintainer) provenance

This version was published by a different npm account (camudo) than the most recent previously approved version (gimenes-decocx) on 2025-12-01, but camudo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.2.3

3 findings
HIGH New file with network + code execution: dist/browser/chunk-6QEXJ7XW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/node/chunk-QP7AQCEP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

3 findings
HIGH New file with network + code execution: dist/browser/chunk-6QEXJ7XW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/node/chunk-QP7AQCEP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.