@glimmer/interfaces
Common interfaces shared among all @glimmer/\* projects
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@simple-dom/interface | AI (phantom-deps): Known glimmer-ecosystem type dependency, used via type-only imports. | ai | |
| vendored-integrity | tampered-vendored-dep:. | AI (vendored-integrity): Sole diff is package.json version bump, matches expected release delta. | ai | |
| phantom-deps | phantom-dep:@glimmer/wire-format | AI (phantom-deps): Same-org sibling package, type-only usage pattern common in Glimmer monorepo. | ai |
Versions (showing 51 of 232)
| Version | Deps | Published |
|---|---|---|
| 0.94.6 | 2 / 3 | |
| 0.94.5 | 1 / 3 | |
| 0.94.4 | 1 / 3 | |
| 0.94.3 | 1 / 3 | |
| 0.94.2 | 1 / 3 | |
| 0.94.1 | 1 / 3 | |
| 0.94.0 | 1 / 3 | |
| 0.93.0 | 1 / 5 | |
| 0.92.3 | 1 / 5 | |
| 0.92.2 | 1 / 5 | |
| 0.92.1 | 1 / 5 | |
| 0.84.3 | 1 / 0 | |
| 0.84.2 | 1 / 0 | |
| 0.84.1 | 1 / 0 | |
| 0.84.0 | 1 / 0 | |
| 0.83.1 | 1 / 0 | |
| 0.83.0 | 1 / 0 | |
| 0.82.0 | 1 / 0 | |
| 0.81.0 | 1 / 0 | |
| 0.80.3 | 1 / 0 | |
| 0.80.2 | 1 / 0 | |
| 0.80.1 | 1 / 0 | |
| 0.80.0 | 1 / 0 | |
| 0.79.4 | 1 / 0 | |
| 0.79.3 | 1 / 0 | |
| 0.79.2 | 1 / 0 | |
| 0.79.1 | 1 / 0 | |
| 0.79.0 | 1 / 0 | |
| 0.78.2 | 1 / 0 | |
| 0.78.1 | 1 / 0 | |
| 0.78.0 | 1 / 0 | |
| 0.77.6 | 1 / 0 | |
| 0.77.5 | 1 / 0 | |
| 0.77.4 | 1 / 0 | |
| 0.77.3 | 1 / 0 | |
| 0.77.2 | 1 / 0 | |
| 0.77.1 | 1 / 0 | |
| 0.77.0 | 1 / 0 | |
| 0.76.0 | 1 / 0 | |
| 0.75.0 | 1 / 0 | |
| 0.74.3 | 1 / 0 | |
| 0.74.2 | 1 / 0 | |
| 0.74.1 | 1 / 0 | |
| 0.74.0 | 1 / 0 | |
| 0.73.2 | 1 / 0 | |
| 0.73.1 | 1 / 0 | |
| 0.73.0 | 1 / 0 | |
| 0.72.0 | 1 / 0 | |
| 0.71.2 | 1 / 0 | |
| 0.71.1 | 1 / 0 | |
| 0.71.0 | 1 / 0 |
v0.94.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.93.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.92.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.92.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.92.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.84.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (chancancode) on 2023-03-23, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.84.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.84.1
2 findingsThe directory `.` byte-matched 45 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.84.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2022-02-15, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.83.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.83.0
2 findingsThe directory `.` byte-matched 43 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/template.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.82.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (pzuraq) on 2021-10-06, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.81.0
3 findingsThe directory `.` byte-matched 43 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/managers/modifier.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (pzuraq) on 2021-09-27, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.80.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.80.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.80.1
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.80.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.4
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.1
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pzuraq) than the most recent previously approved version (chancancode) on 2021-04-27, but pzuraq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.78.2
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (pzuraq) on 2021-04-21, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.78.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (pzuraq) on 2021-04-15, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.77.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.5
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pzuraq) than the most recent previously approved version (rwjblue) on 2021-03-23, but pzuraq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.77.3
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (pzuraq) on 2021-03-16, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.77.1
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pzuraq) than the most recent previously approved version (rwjblue) on 2021-02-17, but pzuraq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.76.0
2 findingsThe directory `.` byte-matched 42 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/wire-format.d.ts, dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pzuraq) than the most recent previously approved version (rwjblue) on 2021-02-09, but pzuraq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.74.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (pzuraq) on 2021-02-12, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.74.2
2 findingsThe directory `.` byte-matched 42 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/wire-format.d.ts, dist/types/lib/template.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.0
3 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pzuraq) than the most recent previously approved version (rwjblue) on 2021-01-30, but pzuraq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.73.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (pzuraq) on 2021-01-21, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.73.1
3 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (pzuraq) on 2020-12-21, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.73.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.72.0
2 findingsThe directory `.` byte-matched 44 of 46 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.1
2 findingsThe directory `.` byte-matched 44 of 45 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.