← Home

@glimmer/interfaces

Common interfaces shared among all @glimmer/\* projects

32
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tomdalerwjbluedgeblockschancancodewycatschadhietalakrisseldenstefanpennermmunmixonicpzuraqglimmer-vm-github-actionsnullvoxpopulief4

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@simple-dom/interface AI (phantom-deps): Known glimmer-ecosystem type dependency, used via type-only imports. ai
vendored-integrity tampered-vendored-dep:. AI (vendored-integrity): Sole diff is package.json version bump, matches expected release delta. ai
phantom-deps phantom-dep:@glimmer/wire-format AI (phantom-deps): Same-org sibling package, type-only usage pattern common in Glimmer monorepo. ai

Versions (showing 32 of 232)

Version Deps Published
0.29.9 1 / 1
0.29.8 1 / 1
0.29.7 1 / 1
0.29.6 1 / 1
0.29.5 1 / 1
0.29.4 1 / 1
0.29.3 1 / 1
0.29.2 1 / 1
0.29.1 1 / 1
0.29.0 1 / 1
0.28.3 1 / 1
0.28.2 1 / 1
0.28.1 1 / 1
0.28.0 1 / 1
0.27.0 1 / 1
0.26.2 1 / 1
0.26.1 1 / 1
0.26.0 1 / 1
0.25.8 1 / 1
0.25.7 1 / 1
0.25.6 1 / 1
0.25.5 1 / 1
0.25.4 1 / 1
0.25.3 1 / 1
0.25.1 1 / 1
0.25.0 1 / 1
0.24.0 1 / 1
0.22.3 1 / 1
0.22.1 1 / 1
0.22.0 1 / 1
0.21.0 1 / 1
0.5.3 1 / 1

v0.29.9

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → chadhietala (on 2017-10-25, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (tomdale) on 2017-10-25, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.29.8

2 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/component-capabilities.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → tomdale (on 2017-10-12, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-10-12, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.29.6

2 findings
HIGH Modified vendored dependency: . (1 file(s)) vendored-integrity

The directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → chadhietala (on 2017-10-10, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (tomdale) on 2017-10-10, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.29.3

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → chadhietala (on 2017-10-05, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (tomdale) on 2017-10-05, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.29.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.1

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → tomdale (on 2017-09-20, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-09-20, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.28.3

3 findings
HIGH Modified vendored dependency: . (1 file(s)) vendored-integrity

The directory `.` byte-matched 12 of 13 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → tomdale (on 2017-09-13, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-09-13, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.28.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chadhietala (on 2017-09-13, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2017-09-13, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → tomdale (on 2017-06-30, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (rwjblue) on 2017-06-30, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.25.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chancancode → wycats (on 2018-10-11, known maintainer) provenance

This version was published by a different npm account (wycats) than the most recent previously approved version (chancancode) on 2018-10-11, but wycats is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.25.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → krisselden (on 2018-05-01, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-05-01, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.25.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → rwjblue (on 2017-10-26, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2017-10-26, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.25.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → rwjblue (on 2017-05-17, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2017-05-17, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.