@everymatrix/casino-my-games
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CasinoMyGames-D7ppRkvw.js | AI (source-diff): Standard minified Svelte runtime + component bundle; no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-rWbM0rp_.js | AI (source-diff): Standard minified build artifact; CustomEvent dispatch and i18n strings are benign. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BlpFP3Ar.js | AI (source-diff): Standard minified build artifact; CustomEvent dispatch and i18n strings are benign. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-xrwkMAx4.js | AI (source-diff): Standard minified build artifact; content is readable casino UI component logic. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-D6dtLFtn.js | AI (source-diff): Standard minified build artifact; content is readable casino UI component logic. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-DwJO0B1j.js | AI (source-diff): Standard minified Svelte/Stencil build output; readable i18n strings confirm legitimate component code. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-aENmJoDx.js | AI (source-diff): Standard minified Svelte/Stencil build output; readable i18n strings confirm legitimate component code. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-Gt0HfzLE.js | AI (source-diff): Consistent with other minified build artifacts in this package. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-DyqQWmVq.js | AI (source-diff): Consistent with other minified build artifacts in this package. | ai | |
| source-diff | obfuscated-file:components/CasinoMyGames-DLk997G6.js | AI (source-diff): Standard minified Svelte runtime + component bundle; no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoMyGames-BDqgiNFb.cjs | AI (source-diff): Svelte runtime bundle; standard minified output for this package family. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-h3rP1TU3.cjs | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-BqMu6kQw.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-Cey9Qjo2.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-BLpjm7DK.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-D8QlEVMA.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BQ5BXrni.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-tnhIaMWM.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoMyGames-B4V77Dqe.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-DKR5BHVb.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoMyGames-DhZS1jH6.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-CVEsXZQR.js | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFavoritesSection-BaXqNnnh.cjs | AI (source-diff): Svelte/Rollup compiled output; readable UI logic in samples, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-n_n_jO0q.cjs | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-921BXKsP.cjs | AI (source-diff): Svelte/Rollup compiled output; readable i18n and UI logic in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-s6Sri_Rt.cjs | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoLastPlayedSection-CRPcTzuF.cjs | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoMostPlayedSection-DPXC4hJ6.cjs | AI (source-diff): Svelte/Rollup compiled output; consistent with package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-D-GlNPZ-.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFavoritesSection-VPbeW4CY.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-DCjhL8aD.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-CYthQkaz.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-C0PUUaqd.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoLastPlayedSection-CBKmtxut.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoMostPlayedSection-C8JhAa1Q.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoMyGames-DBHoF7UM.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-BYrL1mXP.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFavoritesSection-BKOlqlXP.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFavoritesSection-Duo-sU8N.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-Bwl5U9B8.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-ITNdB75n.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-6SLkMLMz.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-yNGXodC1.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-CDQnSCSP.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-M27u1FUo.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-BlK_8Mnj.js | AI (source-diff): Standard Rollup/Vite minified Svelte build output; consistent with package's established build pattern. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Build artifact churn is normal for this actively-versioned component library (601 versions). | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-B5AIZxDy.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable UI logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-ySmCqYSh.js | AI (source-diff): Standard Vite/Rollup minified bundle output for this component library. | ai | |
| source-diff | obfuscated-file:components/CasinoSort-Bm01t1id.js | AI (source-diff): Standard Vite/Rollup minified bundle output for this component library. | ai | |
| source-diff | obfuscated-file:components/CasinoMyGames-H2m8zx8O.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable Svelte runtime, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoMyGames-CME9JF6c.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable Svelte runtime, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-DMUbGFSU.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable UI logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BUu8RYa2.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable UI logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-CfY9zRHU.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable UI logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoGamesCategorySection-BUhdmHfp.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable UI logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoFilter-BqwChYKf.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable UI logic, no malicious patterns. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern for this internal component library across all versions. | ai | |
| provenance | no-provenance | AI (provenance): No provenance has been provided across all versions; stable false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal component library; no description/repo/deps is consistent across all 600 versions of this package. | ai |
Versions (showing 100 of 417)
| Version | Deps | Published |
|---|---|---|
| 1.59.0 | 0 / 0 | |
| 1.58.1 | 0 / 0 | |
| 1.58.0 | 0 / 0 | |
| 1.57.0 | 0 / 0 | |
| 1.56.3 | 0 / 0 | |
| 1.56.2 | 0 / 0 | |
| 1.56.0 | 0 / 0 | |
| 1.55.0 | 0 / 0 | |
| 1.54.12 | 0 / 0 | |
| 1.54.11 | 0 / 0 | |
| 1.54.10 | 0 / 0 | |
| 1.54.9 | 0 / 0 | |
| 1.54.8 | 0 / 0 | |
| 1.54.6 | 0 / 0 | |
| 1.54.4 | 0 / 0 | |
| 1.54.2 | 0 / 0 | |
| 1.54.0 | 3 / 0 | |
| 1.53.12 | 0 / 0 | |
| 1.53.11 | 0 / 0 | |
| 1.53.10 | 0 / 0 | |
| 1.53.0 | 3 / 0 | |
| 1.52.6 | 3 / 0 | |
| 1.52.5 | 3 / 0 | |
| 1.52.4 | 3 / 0 | |
| 1.52.3 | 3 / 0 | |
| 1.52.2 | 3 / 0 | |
| 1.52.1 | 3 / 0 | |
| 1.52.0 | 3 / 0 | |
| 1.51.0 | 3 / 0 | |
| 1.50.1 | 3 / 0 | |
| 1.50.0 | 3 / 0 | |
| 1.49.2 | 3 / 0 | |
| 1.49.1 | 3 / 0 | |
| 1.49.0 | 3 / 0 | |
| 1.48.2 | 3 / 0 | |
| 1.48.1 | 3 / 0 | |
| 1.48.0 | 3 / 0 | |
| 1.47.3 | 3 / 0 | |
| 1.47.2 | 3 / 0 | |
| 1.47.1 | 3 / 0 | |
| 1.47.0 | 3 / 0 | |
| 1.46.1 | 3 / 0 | |
| 1.46.0 | 3 / 0 | |
| 1.45.14 | 3 / 0 | |
| 1.45.13 | 3 / 0 | |
| 1.45.11 | 3 / 0 | |
| 1.45.10 | 3 / 0 | |
| 1.45.9 | 3 / 0 | |
| 1.45.8 | 3 / 0 | |
| 1.45.7 | 3 / 0 | |
| 1.45.6 | 3 / 0 | |
| 1.45.5 | 3 / 0 | |
| 1.45.4 | 3 / 0 | |
| 1.45.3 | 3 / 0 | |
| 1.45.2 | 3 / 0 | |
| 1.45.0 | 3 / 0 | |
| 1.44.0 | 3 / 15 | |
| 1.43.4 | 3 / 15 | |
| 1.43.3 | 3 / 15 | |
| 1.43.2 | 3 / 15 | |
| 1.43.1 | 3 / 15 | |
| 1.43.0 | 3 / 15 | |
| 1.42.0 | 3 / 15 | |
| 1.41.0 | 3 / 15 | |
| 1.40.0 | 3 / 15 | |
| 1.39.3 | 3 / 15 | |
| 1.39.2 | 3 / 15 | |
| 1.39.1 | 3 / 15 | |
| 1.39.0 | 3 / 15 | |
| 1.38.0 | 3 / 15 | |
| 1.37.12 | 3 / 15 | |
| 1.37.11 | 3 / 15 | |
| 1.37.10 | 3 / 15 | |
| 1.37.9 | 3 / 15 | |
| 1.37.8 | 3 / 15 | |
| 1.37.7 | 3 / 15 | |
| 1.37.6 | 3 / 15 | |
| 1.37.5 | 3 / 15 | |
| 1.37.4 | 3 / 15 | |
| 1.37.3 | 3 / 15 | |
| 1.37.2 | 3 / 15 | |
| 1.37.1 | 3 / 15 | |
| 1.37.0 | 3 / 15 | |
| 1.36.1 | 3 / 15 | |
| 1.36.0 | 3 / 15 | |
| 1.35.0 | 3 / 15 | |
| 1.34.3 | 3 / 15 | |
| 1.34.2 | 3 / 15 | |
| 1.34.1 | 3 / 15 | |
| 1.34.0 | 3 / 15 | |
| 1.33.5 | 3 / 15 | |
| 1.33.4 | 3 / 15 | |
| 1.33.3 | 3 / 15 | |
| 1.33.2 | 3 / 15 | |
| 1.33.1 | 3 / 15 | |
| 1.33.0 | 3 / 15 | |
| 1.32.16 | 3 / 15 | |
| 1.32.14 | 3 / 15 | |
| 1.32.13 | 3 / 15 | |
| 1.32.12 | 3 / 15 |
v1.59.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.58.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.58.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.57.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.55.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.