@everymatrix/casino-navigation-search
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:sirv-cli | AI (phantom-deps): Used in start script, not source-imported; standard dev-server dep. | ai | |
| phantom-deps | phantom-dep:svelte | AI (phantom-deps): Framework referenced via svelte field/config, not a direct import. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Used in build/dev scripts, standard CLI env-setter. | ai | |
| source-diff | obfuscated-file:components/CasinoCategoriesProviders-b868yoe6.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-DPZ9O23N.cjs | AI (source-diff): Bundled Stencil/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoProviders-B9qHUUqw.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoNavigationSearch-CvEgXDMX.cjs | AI (source-diff): Bundled svelte/component runtime output. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-CxoRJp_b.cjs | AI (source-diff): Bundled build output incl. moment.js, not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Org-internal maintainer rotation for EveryMatrix scoped package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-internal maintainer rotation for EveryMatrix scoped package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-DAbJt683.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BHm_y5d3.cjs | AI (source-diff): Bundled build output including moment.js, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-DPH_lsJ4.js | AI (source-diff): Bundled build output, ESM equivalent of cjs bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-BlfPG0x2.cjs | AI (source-diff): Bundled Stencil/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoCategoriesProviders-DxKmwl6e.cjs | AI (source-diff): Bundled Stencil/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BUO6p3jL.js | AI (source-diff): Bundled build output, ESM equivalent of cjs bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-B-URKwds.cjs | AI (source-diff): Bundled Stencil/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoProviders-CMVS-Ewf.cjs | AI (source-diff): Bundled Stencil/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoNavigationSearch-T97ixxPr.cjs | AI (source-diff): Bundled Svelte/Stencil runtime helpers, standard minification. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Czy2BrGR.js | AI (source-diff): Bundled build output, consistent with other component files. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Du5QvUcO.js | AI (source-diff): Bundled build output, consistent with other component files. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BMUwvi16.js | AI (source-diff): Standard Rollup/Vite minified build output; same pattern as other bundle files in this package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-y9Hu7PaC.js | AI (source-diff): Standard Rollup/Vite minified build output; consistent with this package's established build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BmHSvVP3.js | AI (source-diff): Standard Rollup/Vite minified build output with hashed filenames; consistent with this package's established build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-B8ruAPZm.js | AI (source-diff): Standard Rollup/Vite minified build output; consistent with this package's established build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-BpFYjbGz.js | AI (source-diff): ESM variant of minified component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-CalP-o1I.cjs | AI (source-diff): Minified Svelte component bundle output; standard for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoCategoriesProviders-ChK7lSMw.cjs | AI (source-diff): Minified web component bundle; i18n translations and custom element registration. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-DwJ4MiwE.cjs | AI (source-diff): Minified RxJS/Svelte component bundle; standard build output. | ai | |
| source-diff | obfuscated-file:components/CasinoNavigationSearch-Di3x_0J5.cjs | AI (source-diff): Minified Svelte component; custom element registration pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoProviders-rtKPIVYL.cjs | AI (source-diff): Minified component with i18n strings; standard build output. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Bevf78kE.cjs | AI (source-diff): Minified search component bundle; standard build output. | ai | |
| source-diff | obfuscated-file:stencil/index-97d17652-ILzgTtTR.cjs | AI (source-diff): Stencil runtime bundle; standard web component framework output. | ai | |
| source-diff | obfuscated-file:stencil/ui-image_2-ZFidgTXM.cjs | AI (source-diff): Stencil UI image component with CSS; standard build output. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-DrneFv8D.js | AI (source-diff): ESM variant of minified component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-eU_vuYrk.js | AI (source-diff): ESM variant of minified component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-d1EHJYWV.js | AI (source-diff): ESM variant of minified component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Bo_XYfW4.js | AI (source-diff): ESM variant of minified component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-CdzsYxkr.js | AI (source-diff): ESM variant of minified component bundle. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Build output with dual CJS/ESM formats produces many files; normal for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-D5CtYtkU.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-KnE4RY5E.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Cho1l1vu.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-DqMfdwi1.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-COVYIHKr.js | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-EyDPHbRr.js | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-BIfo87kb.js | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-DVaxD--r.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoProviders-CXfeouVv.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoNavigationSearch-DdLipJ-m.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-DJvF4m00.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoCategories-B_XS4BnL.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoCategoriesProviders-DwzgJQIC.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Axyir5wR.js | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-4z15LzHk.js | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-UFeFBP15.js | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established release pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent with all other @everymatrix component packages; not a malice indicator here. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is consistent across this package's history; not a new risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Org-wide pattern for @everymatrix scoped components; no repo/deps/description is normal for this publisher. | ai |
Versions (showing 100 of 592)
| Version | Deps | Published |
|---|---|---|
| 1.61.0 | 0 / 0 | |
| 1.60.2 | 0 / 0 | |
| 1.60.1 | 0 / 0 | |
| 1.60.0 | 0 / 0 | |
| 1.59.3 | 0 / 0 | |
| 1.59.2 | 0 / 0 | |
| 1.59.1 | 0 / 0 | |
| 1.59.0 | 0 / 0 | |
| 1.58.1 | 0 / 0 | |
| 1.58.0 | 0 / 0 | |
| 1.57.0 | 0 / 0 | |
| 1.56.3 | 0 / 0 | |
| 1.56.2 | 0 / 0 | |
| 1.56.0 | 0 / 0 | |
| 1.55.0 | 0 / 0 | |
| 1.54.12 | 0 / 0 | |
| 1.54.11 | 0 / 0 | |
| 1.54.10 | 0 / 0 | |
| 1.54.9 | 0 / 0 | |
| 1.54.8 | 0 / 0 | |
| 1.54.6 | 0 / 0 | |
| 1.54.4 | 0 / 0 | |
| 1.54.2 | 0 / 0 | |
| 1.54.0 | 2 / 0 | |
| 1.53.12 | 0 / 0 | |
| 1.53.11 | 0 / 0 | |
| 1.53.10 | 0 / 0 | |
| 1.53.0 | 2 / 0 | |
| 1.52.6 | 2 / 0 | |
| 1.52.5 | 2 / 0 | |
| 1.52.4 | 2 / 0 | |
| 1.52.3 | 2 / 0 | |
| 1.52.2 | 2 / 0 | |
| 1.52.1 | 2 / 0 | |
| 1.52.0 | 2 / 0 | |
| 1.51.0 | 2 / 0 | |
| 1.50.1 | 2 / 0 | |
| 1.50.0 | 2 / 0 | |
| 1.49.2 | 2 / 0 | |
| 1.49.1 | 2 / 0 | |
| 1.49.0 | 2 / 0 | |
| 1.48.2 | 2 / 0 | |
| 1.48.1 | 2 / 0 | |
| 1.48.0 | 2 / 0 | |
| 1.47.3 | 2 / 0 | |
| 1.47.2 | 2 / 0 | |
| 1.47.1 | 2 / 0 | |
| 1.47.0 | 2 / 0 | |
| 1.46.1 | 2 / 0 | |
| 1.46.0 | 2 / 0 | |
| 1.45.14 | 2 / 0 | |
| 1.45.13 | 2 / 0 | |
| 1.45.11 | 2 / 0 | |
| 1.45.10 | 2 / 0 | |
| 1.45.9 | 2 / 0 | |
| 1.45.8 | 2 / 0 | |
| 1.45.7 | 2 / 0 | |
| 1.45.6 | 2 / 0 | |
| 1.45.5 | 2 / 0 | |
| 1.45.4 | 2 / 0 | |
| 1.45.3 | 2 / 0 | |
| 1.45.2 | 2 / 0 | |
| 1.45.0 | 2 / 0 | |
| 1.44.0 | 3 / 15 | |
| 1.43.4 | 3 / 15 | |
| 1.43.3 | 3 / 15 | |
| 1.43.2 | 3 / 15 | |
| 1.43.1 | 3 / 15 | |
| 1.43.0 | 3 / 15 | |
| 1.42.0 | 3 / 15 | |
| 1.41.0 | 3 / 15 | |
| 1.40.0 | 3 / 15 | |
| 1.39.3 | 3 / 15 | |
| 1.39.2 | 3 / 15 | |
| 1.39.1 | 3 / 15 | |
| 1.39.0 | 3 / 15 | |
| 1.38.0 | 3 / 15 | |
| 1.37.12 | 3 / 15 | |
| 1.37.11 | 3 / 15 | |
| 1.37.10 | 3 / 15 | |
| 1.37.9 | 3 / 15 | |
| 1.37.8 | 3 / 15 | |
| 1.37.7 | 3 / 15 | |
| 1.37.6 | 3 / 15 | |
| 1.37.5 | 3 / 15 | |
| 1.37.4 | 3 / 15 | |
| 1.37.3 | 3 / 15 | |
| 1.37.2 | 3 / 15 | |
| 1.37.1 | 3 / 15 | |
| 1.37.0 | 3 / 15 | |
| 1.36.1 | 3 / 15 | |
| 1.36.0 | 3 / 15 | |
| 1.35.0 | 3 / 15 | |
| 1.34.3 | 3 / 15 | |
| 1.34.2 | 3 / 15 | |
| 1.34.1 | 3 / 15 | |
| 1.34.0 | 3 / 15 | |
| 1.33.5 | 3 / 15 | |
| 1.33.4 | 3 / 15 | |
| 1.33.3 | 3 / 15 |
v1.61.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.60.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.60.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.60.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.59.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.59.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.59.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.59.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.58.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.58.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.57.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.55.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.