@everymatrix/casino-lobby
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@everymatrix/casino-modal | AI (phantom-deps): Same-org scoped dep; typical for monorepo packages with shared components. | ai | |
| phantom-deps | phantom-dep:@everymatrix/casino-categories-slider | AI (phantom-deps): Same-org scoped dep; typical for monorepo packages with shared components. | ai | |
| phantom-deps | phantom-dep:@everymatrix/casino-game-page | AI (phantom-deps): Same-org scoped dep; typical for monorepo packages with shared components. | ai | |
| phantom-deps | phantom-dep:@everymatrix/casino-page | AI (phantom-deps): Same-org scoped dep; typical for monorepo packages with shared components. | ai | |
| phantom-deps | phantom-dep:svelte | AI (phantom-deps): Core framework dep, referenced via svelte field/config. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Used in build/dev scripts. | ai | |
| phantom-deps | phantom-dep:sirv-cli | AI (phantom-deps): Used in package.json start script. | ai | |
| source-diff | obfuscated-file:components/CasinoCalendarDailyItem-C3xfp-OS.cjs | AI (source-diff): Bundled build output, same pattern across component files. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-Dg2U96dy.cjs | AI (source-diff): Bundled build output, same pattern across component files. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-CFym68mv.cjs | AI (source-diff): Bundled build output, same pattern across component files. | ai | |
| source-diff | obfuscated-file:components/CasinoFavoritesSection-DE_s0gS_.cjs | AI (source-diff): Bundled build output, same pattern across component files. | ai | |
| source-diff | obfuscated-file:components/CasinoCollectionsProviders-BX2V3tDm.cjs | AI (source-diff): Bundled build output, same pattern across component files. | ai | |
| source-diff | obfuscated-file:components/CasinoCategoriesSlider-BTw-gZW4.cjs | AI (source-diff): Bundled build output, same pattern across component files. | ai | |
| source-diff | obfuscated-file:components/CasinoCalendarDailyDetails-VGdSGrVK.cjs | AI (source-diff): Minified Svelte/Stencil build output, not obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-DDc1Do7_.cjs | AI (source-diff): Bundled Svelte/Stencil build output, no malicious behavior. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Routine maintainer rotation for an established multi-year package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Routine maintainer rotation for an established multi-year package. | ai | |
| source-diff | obfuscated-file:components/CasinoLobby-DeYBdEoa.cjs | AI (source-diff): Bundled Svelte component output, not true obfuscation; recurring pattern for this UI library. | ai | |
| source-diff | obfuscated-file:components/CasinoLobby-CmAf2BJ4.js | AI (source-diff): Bundled Stencil/vite build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoLobby-DlkT0ycq.js | AI (source-diff): Bundled Stencil/vite build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoLobby-DIkig4WG.cjs | AI (source-diff): Bundled Svelte component output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:stencil/index-328e660d-C6OCQOhB.cjs | AI (source-diff): Standard Stencil build artifact for this casino lobby component library. | ai | |
| source-diff | obfuscated-file:stencil/casino-play-random-game_2-CCCLDakd.cjs | AI (source-diff): Minified Stencil component bundle; no malicious indicators in sample. | ai | |
| source-diff | obfuscated-file:components/CasinoCalendar-CPSaANk_.cjs | AI (source-diff): Standard Svelte/Vite minified build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoPage-Z_i9BoVq.cjs | AI (source-diff): Standard Svelte/Vite minified build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-BMVgv-gE.cjs | AI (source-diff): Standard Svelte/Vite minified build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoLobby-CTZObrkO.cjs | AI (source-diff): Standard Svelte/Vite minified build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:stencil/casino-play-random-game_2-cZvlv_fo.cjs | AI (source-diff): Minified Stencil component build artifact; samples show legitimate UI component code. | ai | |
| source-diff | obfuscated-file:components/CasinoCalendar-Bh1m4DYa.cjs | AI (source-diff): Standard minified Svelte build output for this casino lobby component package; consistent across all versions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Component library regularly adds new UI components across versions; 86 new files is consistent with feature expansion. | ai | |
| source-diff | obfuscated-file:stencil/index-328e660d-BN7c7sEP.cjs | AI (source-diff): Standard minified Stencil runtime artifact for this UI component library. | ai | |
| source-diff | obfuscated-file:stencil/casino-play-random-game_2-ZYQBmsCp.cjs | AI (source-diff): Standard minified Stencil build artifact; readable UI logic visible in sample. | ai | |
| source-diff | obfuscated-file:components/CasinoLobby-DCWkhIQL.cjs | AI (source-diff): Standard minified Svelte build artifact; readable UI code visible in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoCalendar-CLr-MrQT.cjs | AI (source-diff): Standard minified Svelte build artifact for casino UI component; consistent with package purpose. | ai | |
| source-diff | obfuscated-file:stencil/index-328e660d-BLQrzwBv.cjs | AI (source-diff): Standard minified Stencil runtime bundle for this package. | ai | |
| source-diff | obfuscated-file:stencil/casino-play-random-game_2-CBAgufN5.cjs | AI (source-diff): Minified Stencil component bundle; readable UI strings and DOM ops, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoCalendar-CDybCkBw.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern across all versions of this internal package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal component package with 1016 versions; no repo/description is consistent across all releases. | ai | |
| provenance | no-provenance | AI (provenance): No provenance has been provided across any version; stable false positive for this package. | ai |
Versions (showing 100 of 691)
| Version | Deps | Published |
|---|---|---|
| 1.57.0 | 0 / 0 | |
| 1.56.3 | 0 / 0 | |
| 1.56.2 | 0 / 0 | |
| 1.56.0 | 0 / 0 | |
| 1.55.0 | 0 / 0 | |
| 1.54.12 | 0 / 0 | |
| 1.54.11 | 0 / 0 | |
| 1.54.10 | 0 / 0 | |
| 1.54.9 | 1 / 0 | |
| 1.54.8 | 1 / 0 | |
| 1.54.6 | 0 / 0 | |
| 1.54.4 | 0 / 0 | |
| 1.54.3 | 0 / 0 | |
| 1.54.2 | 0 / 0 | |
| 1.54.0 | 4 / 0 | |
| 1.53.12 | 0 / 0 | |
| 1.53.11 | 0 / 0 | |
| 1.53.10 | 0 / 0 | |
| 1.53.0 | 4 / 0 | |
| 1.52.6 | 4 / 0 | |
| 1.52.5 | 4 / 0 | |
| 1.52.4 | 4 / 0 | |
| 1.52.3 | 4 / 0 | |
| 1.52.2 | 4 / 0 | |
| 1.52.1 | 4 / 0 | |
| 1.52.0 | 4 / 0 | |
| 1.51.0 | 4 / 0 | |
| 1.50.1 | 4 / 0 | |
| 1.50.0 | 4 / 0 | |
| 1.49.2 | 4 / 0 | |
| 1.49.1 | 4 / 0 | |
| 1.49.0 | 4 / 0 | |
| 1.48.2 | 4 / 0 | |
| 1.48.1 | 4 / 0 | |
| 1.48.0 | 4 / 0 | |
| 1.47.4 | 4 / 0 | |
| 1.47.3 | 4 / 0 | |
| 1.47.2 | 4 / 0 | |
| 1.47.1 | 4 / 0 | |
| 1.47.0 | 4 / 0 | |
| 1.46.1 | 4 / 0 | |
| 1.46.0 | 4 / 0 | |
| 1.45.14 | 4 / 0 | |
| 1.45.13 | 4 / 0 | |
| 1.45.11 | 4 / 0 | |
| 1.45.10 | 4 / 0 | |
| 1.45.9 | 4 / 0 | |
| 1.45.8 | 4 / 0 | |
| 1.45.7 | 4 / 0 | |
| 1.45.6 | 4 / 0 | |
| 1.45.5 | 4 / 0 | |
| 1.45.4 | 4 / 0 | |
| 1.45.3 | 4 / 0 | |
| 1.45.2 | 4 / 0 | |
| 1.45.0 | 4 / 0 | |
| 1.44.0 | 3 / 15 | |
| 1.43.4 | 3 / 15 | |
| 1.43.3 | 3 / 15 | |
| 1.43.2 | 3 / 15 | |
| 1.43.1 | 3 / 15 | |
| 1.43.0 | 3 / 15 | |
| 1.42.69 | 0 / 0 | |
| 1.42.0 | 3 / 15 | |
| 1.41.0 | 3 / 15 | |
| 1.40.0 | 3 / 15 | |
| 1.39.3 | 3 / 15 | |
| 1.39.2 | 3 / 15 | |
| 1.39.1 | 3 / 15 | |
| 1.39.0 | 3 / 15 | |
| 1.38.0 | 3 / 15 | |
| 1.37.12 | 3 / 15 | |
| 1.37.11 | 3 / 15 | |
| 1.37.10 | 3 / 15 | |
| 1.37.9 | 3 / 15 | |
| 1.37.8 | 3 / 15 | |
| 1.37.7 | 3 / 15 | |
| 1.37.6 | 3 / 15 | |
| 1.37.5 | 3 / 15 | |
| 1.37.4 | 3 / 15 | |
| 1.37.3 | 3 / 15 | |
| 1.37.2 | 3 / 15 | |
| 1.37.1 | 3 / 15 | |
| 1.37.0 | 3 / 15 | |
| 1.36.1 | 3 / 15 | |
| 1.36.0 | 3 / 15 | |
| 1.35.0 | 3 / 15 | |
| 1.34.3 | 3 / 15 | |
| 1.34.2 | 3 / 15 | |
| 1.34.1 | 3 / 15 | |
| 1.34.0 | 3 / 15 | |
| 1.33.5 | 3 / 15 | |
| 1.33.4 | 3 / 15 | |
| 1.33.3 | 3 / 15 | |
| 1.33.2 | 3 / 15 | |
| 1.33.1 | 3 / 15 | |
| 1.33.0 | 3 / 15 | |
| 1.32.16 | 3 / 15 | |
| 1.32.14 | 3 / 15 | |
| 1.32.13 | 3 / 15 | |
| 1.32.12 | 3 / 15 |
v1.57.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.55.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.