← Home

@glimmer/interfaces

Common interfaces shared among all @glimmer/\* projects

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tomdalerwjbluedgeblockschancancodewycatschadhietalakrisseldenstefanpennermmunmixonicpzuraqglimmer-vm-github-actionsnullvoxpopulief4

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@simple-dom/interface AI (phantom-deps): Known glimmer-ecosystem type dependency, used via type-only imports. ai
vendored-integrity tampered-vendored-dep:. AI (vendored-integrity): Sole diff is package.json version bump, matches expected release delta. ai
phantom-deps phantom-dep:@glimmer/wire-format AI (phantom-deps): Same-org sibling package, type-only usage pattern common in Glimmer monorepo. ai

Versions (showing 100 of 232)

Version Deps Published
0.53.0 1 / 0
0.52.1 1 / 0
0.52.0 1 / 0
0.51.1 1 / 0
0.51.0 1 / 0
0.50.4 1 / 0
0.50.3 1 / 0
0.50.2 1 / 0
0.50.0 1 / 0
0.49.0 1 / 0
0.48.0 1 / 0
0.47.9 1 / 0
0.47.8 1 / 0
0.47.7 1 / 0
0.47.6 1 / 0
0.47.5 1 / 0
0.47.4 1 / 0
0.47.3 1 / 0
0.47.1 1 / 0
0.47.0 1 / 0
0.46.0 1 / 0
0.45.3 1 / 0
0.45.2 0 / 1
0.45.1 0 / 1
0.45.0 0 / 1
0.44.0 0 / 1
0.43.0 0 / 1
0.42.2 0 / 1
0.42.1 0 / 1
0.42.0 0 / 1
0.41.4 0 / 1
0.41.3 0 / 1
0.41.1 0 / 1
0.41.0 0 / 1
0.40.2 0 / 1
0.40.1 0 / 1
0.40.0 0 / 1
0.39.3 0 / 1
0.39.2 0 / 1
0.39.1 0 / 1
0.39.0 0 / 1
0.38.4 2 / 1
0.38.3 2 / 1
0.38.2 2 / 1
0.38.0 2 / 1
0.37.1 2 / 1
0.37.0 2 / 1
0.36.6 1 / 1
0.36.4 1 / 1
0.36.3 1 / 1
0.36.2 1 / 1
0.36.1 1 / 1
0.36.0 1 / 1
0.35.11 1 / 1
0.35.10 1 / 1
0.35.9 1 / 1
0.35.8 1 / 1
0.35.7 1 / 1
0.35.6 1 / 1
0.35.5 1 / 1
0.35.4 1 / 1
0.35.3 1 / 1
0.35.2 1 / 1
0.35.1 1 / 1
0.35.0 1 / 1
0.34.8 1 / 1
0.34.7 1 / 1
0.34.6 1 / 1
0.34.5 1 / 1
0.34.4 1 / 1
0.34.3 1 / 1
0.34.2 1 / 1
0.34.1 1 / 1
0.34.0 1 / 1
0.33.7 1 / 1
0.33.6 1 / 1
0.33.5 1 / 1
0.33.4 1 / 1
0.33.3 1 / 1
0.33.2 1 / 1
0.33.1 1 / 1
0.33.0 1 / 1
0.32.9 1 / 1
0.32.8 1 / 1
0.32.7 1 / 1
0.32.6 1 / 1
0.32.5 1 / 1
0.32.4 1 / 1
0.32.3 1 / 1
0.32.2 1 / 1
0.32.1 1 / 1
0.32.0 1 / 1
0.31.0 1 / 1
0.30.5 1 / 1
0.30.4 1 / 1
0.30.3 1 / 1
0.30.2 1 / 1
0.30.1 1 / 1
0.30.0 1 / 1
0.29.10 1 / 1
Showing 100 of 232 Next page →

v0.53.0

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.52.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.52.0

2 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/wire-format.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.51.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.51.0

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.3

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.49.0

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.9

2 findings
HIGH Modified vendored dependency: . (5 file(s)) vendored-integrity

The directory `.` byte-matched 32 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 5 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/wire-format.d.ts, dist/types/lib/runtime/element.d.ts, dist/types/lib/vm-opcodes.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.7

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.5

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chancancode (on 2020-02-07, known maintainer) provenance

This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2020-02-07, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.47.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.3

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chancancode (on 2020-01-28, known maintainer) provenance

This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2020-01-28, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.47.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.47.0

2 findings
HIGH Modified vendored dependency: . (4 file(s)) vendored-integrity

The directory `.` byte-matched 33 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/operands.d.ts, dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.3

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.1

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.44.0

2 findings
HIGH Modified vendored dependency: . (4 file(s)) vendored-integrity

The directory `.` byte-matched 33 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/components/component-manager.d.ts, dist/types/lib/runtime/arguments.d.ts, dist/types/lib/runtime/modifier.d.ts, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.42.2

2 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/operands.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.42.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.42.0

2 findings
HIGH Modified vendored dependency: . (1 file(s)) vendored-integrity

The directory `.` byte-matched 36 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.3

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.0

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.40.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → rwjblue (on 2019-05-13, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-05-13, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.40.1

3 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/dom/attributes.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → rwjblue (on 2019-04-16, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-04-16, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.40.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chancancode → tomdale (on 2019-04-08, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (chancancode) on 2019-04-08, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.39.3

3 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/components/component-manager.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → rwjblue (on 2019-03-15, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-03-15, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.39.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.39.1

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.39.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → tomdale (on 2019-02-06, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (rwjblue) on 2019-02-06, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.38.4

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → chancancode (on 2019-04-03, known maintainer) provenance

This version was published by a different npm account (chancancode) than the most recent previously approved version (tomdale) on 2019-04-03, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.38.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → chancancode (on 2019-04-03, known maintainer) provenance

This version was published by a different npm account (chancancode) than the most recent previously approved version (tomdale) on 2019-04-03, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.38.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → rwjblue (on 2019-01-04, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-01-04, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.37.1

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: wycats → tomdale (on 2018-11-29, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (wycats) on 2018-11-29, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.36.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.36.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.36.3

3 findings
HIGH Modified vendored dependency: . (1 file(s)) vendored-integrity

The directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chancancode (on 2018-09-25, known maintainer) provenance

This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2018-09-25, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.36.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → rwjblue (on 2018-09-07, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-09-07, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.36.1

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → rwjblue (on 2018-09-05, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-09-05, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.36.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → chadhietala (on 2018-08-28, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (krisselden) on 2018-08-28, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.35.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tomdale → rwjblue (on 2019-01-22, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-01-22, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.35.10

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.9

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chancancode (on 2018-09-25, known maintainer) provenance

This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2018-09-25, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.35.8

3 findings
HIGH Modified vendored dependency: . (1 file(s)) vendored-integrity

The directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → rwjblue (on 2018-09-06, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-09-06, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.35.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → krisselden (on 2018-06-29, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-06-29, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.35.5

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.3

2 findings
HIGH Modified vendored dependency: . (1 file(s)) vendored-integrity

The directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → rwjblue (on 2018-06-04, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-06-04, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.35.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chadhietala (on 2018-06-04, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2018-06-04, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.35.0

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.7

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → tomdale (on 2018-05-28, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (rwjblue) on 2018-05-28, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.34.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-05-27, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-05-27, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.34.5

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-05-21, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-05-21, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.34.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → chadhietala (on 2018-05-19, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (krisselden) on 2018-05-19, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.34.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.1

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → krisselden (on 2018-04-25, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-04-25, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.34.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.7

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-04-18, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-18, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.33.5

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-04-16, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-16, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.33.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → krisselden (on 2018-03-22, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.33.3

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → krisselden (on 2018-03-22, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.33.2

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → krisselden (on 2018-03-22, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.33.1

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → krisselden (on 2018-03-22, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.33.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chadhietala (on 2018-03-07, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2018-03-07, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.32.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.8

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → krisselden (on 2018-04-26, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-04-26, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.32.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.6

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-04-18, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-18, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.32.4

3 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-04-16, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-16, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.32.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chadhietala (on 2018-03-01, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2018-03-01, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.32.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-03-01, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-03-01, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.32.1

3 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → rwjblue (on 2018-02-25, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-02-25, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.32.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.31.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: krisselden → tomdale (on 2018-02-08, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (krisselden) on 2018-02-08, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.30.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → krisselden (on 2018-01-23, known maintainer) provenance

This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-01-23, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.30.4

3 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → rwjblue (on 2018-01-12, known maintainer) provenance

This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-01-12, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.30.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.30.2

3 findings
HIGH Modified vendored dependency: . (3 file(s)) vendored-integrity

The directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chadhietala → tomdale (on 2017-11-14, known maintainer) provenance

This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-11-14, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.30.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chadhietala (on 2017-11-08, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2017-11-08, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.30.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rwjblue → chadhietala (on 2017-11-08, known maintainer) provenance

This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2017-11-08, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.29.10

2 findings
HIGH Modified vendored dependency: . (2 file(s)) vendored-integrity

The directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.