@escapenavigator/services
// полезные
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established org package with consistent publish history; lack of Sigstore provenance is a process gap, not a security signal here. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Library dependency referenced in config/type declarations; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:date-fns-tz | AI (phantom-deps): Library dependency referenced in config/type declarations; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:class-transformer | AI (phantom-deps): Internal monorepo package; deps declared for peer/config use, not direct import. | ai | |
| phantom-deps | phantom-dep:i18next | AI (phantom-deps): Internal monorepo package; deps declared for peer/config use, not direct import. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped package; missing repo/readme/keywords is consistent across all 380 versions. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Internal monorepo package; deps declared for peer/config use, not direct import. | ai | |
| phantom-deps | phantom-dep:class-validator | AI (phantom-deps): Internal monorepo package; deps declared for peer/config use, not direct import. | ai |
Versions (showing 51 of 123)
| Version | Deps | Published |
|---|---|---|
| 1.10.155 | 8 / 1 | |
| 1.10.154 | 8 / 1 | |
| 1.10.153 | 8 / 1 | |
| 1.10.152 | 8 / 1 | |
| 1.10.151 | 8 / 1 | |
| 1.10.150 | 8 / 1 | |
| 1.10.149 | 8 / 1 | |
| 1.10.148 | 8 / 1 | |
| 1.10.147 | 8 / 1 | |
| 1.10.146 | 8 / 1 | |
| 1.10.145 | 8 / 1 | |
| 1.10.144 | 8 / 1 | |
| 1.10.143 | 8 / 1 | |
| 1.10.142 | 8 / 1 | |
| 1.10.141 | 8 / 1 | |
| 1.10.140 | 8 / 1 | |
| 1.10.139 | 8 / 1 | |
| 1.10.138 | 8 / 1 | |
| 1.10.137 | 8 / 1 | |
| 1.10.136 | 8 / 1 | |
| 1.10.135 | 8 / 1 | |
| 1.10.134 | 8 / 1 | |
| 1.10.133 | 8 / 1 | |
| 1.10.132 | 8 / 1 | |
| 1.10.131 | 8 / 1 | |
| 1.10.130 | 8 / 1 | |
| 1.10.117 | 8 / 1 | |
| 1.10.116 | 8 / 1 | |
| 1.10.115 | 8 / 1 | |
| 1.10.114 | 8 / 1 | |
| 1.10.113 | 8 / 1 | |
| 1.10.112 | 10 / 15 | |
| 1.10.111 | 10 / 15 | |
| 1.10.110 | 10 / 15 | |
| 1.10.109 | 10 / 15 | |
| 1.10.108 | 10 / 15 | |
| 1.10.107 | 10 / 15 | |
| 1.10.106 | 10 / 15 | |
| 1.10.105 | 10 / 15 | |
| 1.10.104 | 10 / 15 | |
| 1.10.103 | 10 / 15 | |
| 1.10.101 | 10 / 15 | |
| 1.10.100 | 10 / 15 | |
| 1.10.99 | 10 / 15 | |
| 1.10.98 | 10 / 15 | |
| 1.10.97 | 10 / 15 | |
| 1.10.96 | 10 / 15 | |
| 1.10.95 | 10 / 15 | |
| 1.10.94 | 10 / 15 | |
| 1.10.93 | 10 / 15 | |
| 1.10.91 | 10 / 15 |
v1.10.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.154
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.153
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.152
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.150
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.149
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.148
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.147
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.146
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.145
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.144
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.143
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.142
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.141
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.140
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.139
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.138
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.137
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.136
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.135
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.134
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.133
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.132
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.131
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.130
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.117
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.116
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.115
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.114
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.113
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.112
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.111
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.110
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.109
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.108
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.107
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.106
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.105
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.104
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.103
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.101
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.100
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.99
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.98
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.97
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.96
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.95
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.94
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.93
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.91
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.