@glimmer/interfaces
Common interfaces shared among all @glimmer/\* projects
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@simple-dom/interface | AI (phantom-deps): Known glimmer-ecosystem type dependency, used via type-only imports. | ai | |
| vendored-integrity | tampered-vendored-dep:. | AI (vendored-integrity): Sole diff is package.json version bump, matches expected release delta. | ai | |
| phantom-deps | phantom-dep:@glimmer/wire-format | AI (phantom-deps): Same-org sibling package, type-only usage pattern common in Glimmer monorepo. | ai |
Versions (showing 100 of 232)
| Version | Deps | Published |
|---|---|---|
| 0.53.0 | 1 / 0 | |
| 0.52.1 | 1 / 0 | |
| 0.52.0 | 1 / 0 | |
| 0.51.1 | 1 / 0 | |
| 0.51.0 | 1 / 0 | |
| 0.50.4 | 1 / 0 | |
| 0.50.3 | 1 / 0 | |
| 0.50.2 | 1 / 0 | |
| 0.50.0 | 1 / 0 | |
| 0.49.0 | 1 / 0 | |
| 0.48.0 | 1 / 0 | |
| 0.47.9 | 1 / 0 | |
| 0.47.8 | 1 / 0 | |
| 0.47.7 | 1 / 0 | |
| 0.47.6 | 1 / 0 | |
| 0.47.5 | 1 / 0 | |
| 0.47.4 | 1 / 0 | |
| 0.47.3 | 1 / 0 | |
| 0.47.1 | 1 / 0 | |
| 0.47.0 | 1 / 0 | |
| 0.46.0 | 1 / 0 | |
| 0.45.3 | 1 / 0 | |
| 0.45.2 | 0 / 1 | |
| 0.45.1 | 0 / 1 | |
| 0.45.0 | 0 / 1 | |
| 0.44.0 | 0 / 1 | |
| 0.43.0 | 0 / 1 | |
| 0.42.2 | 0 / 1 | |
| 0.42.1 | 0 / 1 | |
| 0.42.0 | 0 / 1 | |
| 0.41.4 | 0 / 1 | |
| 0.41.3 | 0 / 1 | |
| 0.41.1 | 0 / 1 | |
| 0.41.0 | 0 / 1 | |
| 0.40.2 | 0 / 1 | |
| 0.40.1 | 0 / 1 | |
| 0.40.0 | 0 / 1 | |
| 0.39.3 | 0 / 1 | |
| 0.39.2 | 0 / 1 | |
| 0.39.1 | 0 / 1 | |
| 0.39.0 | 0 / 1 | |
| 0.38.4 | 2 / 1 | |
| 0.38.3 | 2 / 1 | |
| 0.38.2 | 2 / 1 | |
| 0.38.0 | 2 / 1 | |
| 0.37.1 | 2 / 1 | |
| 0.37.0 | 2 / 1 | |
| 0.36.6 | 1 / 1 | |
| 0.36.4 | 1 / 1 | |
| 0.36.3 | 1 / 1 | |
| 0.36.2 | 1 / 1 | |
| 0.36.1 | 1 / 1 | |
| 0.36.0 | 1 / 1 | |
| 0.35.11 | 1 / 1 | |
| 0.35.10 | 1 / 1 | |
| 0.35.9 | 1 / 1 | |
| 0.35.8 | 1 / 1 | |
| 0.35.7 | 1 / 1 | |
| 0.35.6 | 1 / 1 | |
| 0.35.5 | 1 / 1 | |
| 0.35.4 | 1 / 1 | |
| 0.35.3 | 1 / 1 | |
| 0.35.2 | 1 / 1 | |
| 0.35.1 | 1 / 1 | |
| 0.35.0 | 1 / 1 | |
| 0.34.8 | 1 / 1 | |
| 0.34.7 | 1 / 1 | |
| 0.34.6 | 1 / 1 | |
| 0.34.5 | 1 / 1 | |
| 0.34.4 | 1 / 1 | |
| 0.34.3 | 1 / 1 | |
| 0.34.2 | 1 / 1 | |
| 0.34.1 | 1 / 1 | |
| 0.34.0 | 1 / 1 | |
| 0.33.7 | 1 / 1 | |
| 0.33.6 | 1 / 1 | |
| 0.33.5 | 1 / 1 | |
| 0.33.4 | 1 / 1 | |
| 0.33.3 | 1 / 1 | |
| 0.33.2 | 1 / 1 | |
| 0.33.1 | 1 / 1 | |
| 0.33.0 | 1 / 1 | |
| 0.32.9 | 1 / 1 | |
| 0.32.8 | 1 / 1 | |
| 0.32.7 | 1 / 1 | |
| 0.32.6 | 1 / 1 | |
| 0.32.5 | 1 / 1 | |
| 0.32.4 | 1 / 1 | |
| 0.32.3 | 1 / 1 | |
| 0.32.2 | 1 / 1 | |
| 0.32.1 | 1 / 1 | |
| 0.32.0 | 1 / 1 | |
| 0.31.0 | 1 / 1 | |
| 0.30.5 | 1 / 1 | |
| 0.30.4 | 1 / 1 | |
| 0.30.3 | 1 / 1 | |
| 0.30.2 | 1 / 1 | |
| 0.30.1 | 1 / 1 | |
| 0.30.0 | 1 / 1 | |
| 0.29.10 | 1 / 1 |
v0.53.0
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.52.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.52.0
2 findingsThe directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/wire-format.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.0
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.3
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.0
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.9
2 findingsThe directory `.` byte-matched 32 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 5 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/wire-format.d.ts, dist/types/lib/runtime/element.d.ts, dist/types/lib/vm-opcodes.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.7
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.5
3 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2020-02-07, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.47.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.3
3 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2020-01-28, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.47.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.0
2 findingsThe directory `.` byte-matched 33 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/operands.d.ts, dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.3
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.1
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.0
2 findingsThe directory `.` byte-matched 33 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/components/component-manager.d.ts, dist/types/lib/runtime/arguments.d.ts, dist/types/lib/runtime/modifier.d.ts, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.2
2 findingsThe directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/compile/operands.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.0
2 findingsThe directory `.` byte-matched 36 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.3
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.0
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-05-13, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.40.1
3 findingsThe directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/dom/attributes.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-04-16, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.40.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (chancancode) on 2019-04-08, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.39.3
3 findingsThe directory `.` byte-matched 34 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/components/component-manager.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-03-15, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.39.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.39.1
2 findingsThe directory `.` byte-matched 35 of 37 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.39.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (rwjblue) on 2019-02-06, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.38.4
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.38.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (tomdale) on 2019-04-03, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.38.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (tomdale) on 2019-04-03, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.38.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-01-04, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.37.1
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (wycats) on 2018-11-29, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.36.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.3
3 findingsThe directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2018-09-25, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.36.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-09-07, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.36.1
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-09-05, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.36.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (krisselden) on 2018-08-28, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.35.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (tomdale) on 2019-01-22, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.35.10
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chancancode) than the most recent previously approved version (rwjblue) on 2018-09-25, but chancancode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.35.8
3 findingsThe directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-09-06, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.35.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-06-29, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.35.5
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.3
2 findingsThe directory `.` byte-matched 15 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-06-04, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.35.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2018-06-04, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.35.0
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.7
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (rwjblue) on 2018-05-28, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.34.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-05-27, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.34.5
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-05-21, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.34.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (krisselden) on 2018-05-19, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.34.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.1
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-04-25, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.7
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-18, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.33.5
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-16, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.33.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.33.3
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.33.2
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.33.1
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-03-22, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.33.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2018-03-07, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.32.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.8
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (rwjblue) on 2018-04-26, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.32.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.6
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-18, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.32.4
3 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-04-16, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.32.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2018-03-01, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.32.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-03-01, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.32.1
3 findingsThe directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (krisselden) on 2018-02-25, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (krisselden) on 2018-02-08, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.30.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (krisselden) than the most recent previously approved version (chadhietala) on 2018-01-23, but krisselden is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.30.4
3 findingsThe directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rwjblue) than the most recent previously approved version (chadhietala) on 2018-01-12, but rwjblue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.30.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.2
3 findingsThe directory `.` byte-matched 13 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 3 file(s) inside it differ from that package's bytes at the same path: dist/types/lib/program.d.ts, dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tomdale) than the most recent previously approved version (chadhietala) on 2017-11-14, but tomdale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.30.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2017-11-08, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.30.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chadhietala) than the most recent previously approved version (rwjblue) on 2017-11-08, but chadhietala is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.29.10
2 findingsThe directory `.` byte-matched 14 of 16 file(s) against @glimmer/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 2 file(s) inside it differ from that package's bytes at the same path: dist/types/package.json, package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @glimmer/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.