@emilgroup/payment-sdk-node
OpenAPI client for @emilgroup/payment-sdk-node
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 1.28.0 | 3 / 2 | |
| 1.26.0 | 3 / 2 | |
| 1.21.0 | 3 / 2 | |
| 1.17.0 | 3 / 2 | |
| 1.16.0 | 3 / 2 | |
| 1.14.0 | 3 / 2 | |
| 1.12.1 | 3 / 2 | |
| 1.8.2 | 3 / 2 |
v1.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.26.0
3 findingsAll previous maintainers (cover42devs) were replaced by new maintainers (ahmed.zeno, adobrodey-emil, pavlomaksymov, alexandrecastro, alexeyoleynik, edgar-emil, emil_engineering, jonathan.chen, wojciech_at_emil, maksym-emil, yevheniia-emil, emil_aleksandra, vitaly_emil, andrii_meleniuk, iaroslav.ovcharenko, hussein.istanbouli, thomascover42, emil-hussein, thmd, rkachalka, zamiul, emil-rick, mads-emil, olga_timchenko). This is a strong signal of a potential package hijack and requires careful review.
This version was published by a different npm account than previous versions on 2026-07-20. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.