@glimmer/interfaces
Common interfaces shared among all @glimmer/\* projects
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@simple-dom/interface | AI (phantom-deps): Known glimmer-ecosystem type dependency, used via type-only imports. | ai | |
| vendored-integrity | tampered-vendored-dep:. | AI (vendored-integrity): Sole diff is package.json version bump, matches expected release delta. | ai | |
| phantom-deps | phantom-dep:@glimmer/wire-format | AI (phantom-deps): Same-org sibling package, type-only usage pattern common in Glimmer monorepo. | ai |
Versions (showing 32 of 232)
| Version | Deps | Published |
|---|---|---|
| 0.29.9 | 1 / 1 | |
| 0.29.8 | 1 / 1 | |
| 0.29.7 | 1 / 1 | |
| 0.29.6 | 1 / 1 | |
| 0.29.5 | 1 / 1 | |
| 0.29.4 | 1 / 1 | |
| 0.29.3 | 1 / 1 | |
| 0.29.2 | 1 / 1 | |
| 0.29.1 | 1 / 1 | |
| 0.29.0 | 1 / 1 | |
| 0.28.3 | 1 / 1 | |
| 0.28.2 | 1 / 1 | |
| 0.28.1 | 1 / 1 | |
| 0.28.0 | 1 / 1 | |
| 0.27.0 | 1 / 1 | |
| 0.26.2 | 1 / 1 | |
| 0.26.1 | 1 / 1 | |
| 0.26.0 | 1 / 1 | |
| 0.25.8 | 1 / 1 | |
| 0.25.7 | 1 / 1 | |
| 0.25.6 | 1 / 1 | |
| 0.25.5 | 1 / 1 | |
| 0.25.4 | 1 / 1 | |
| 0.25.3 | 1 / 1 | |
| 0.25.1 | 1 / 1 | |
| 0.25.0 | 1 / 1 | |
| 0.24.0 | 1 / 1 | |
| 0.22.3 | 1 / 1 | |
| 0.22.1 | 1 / 1 | |
| 0.22.0 | 1 / 1 | |
| 0.21.0 | 1 / 1 | |
| 0.5.3 | 1 / 1 |
v0.29.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (tomdale) on 2017-10-25, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.29.8
2 findingsThe directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/component-capabilities.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-10-12, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.29.6
2 findingsThe directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (tomdale) on 2017-10-10, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.29.3
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (tomdale) on 2017-10-05, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.29.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.1
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-09-20, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.28.3
3 findingsThe directory `.` byte-matched 12 of 13 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-09-13, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2017-09-13, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (rwjblue) on 2017-06-30, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.25.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wycats) than the most recent previously approved version (chancancode) on 2018-10-11, but wycats is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.25.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-05-01, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.25.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2017-10-26, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.25.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2017-05-17, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.