@graphql-toolkit/graphql-tag-pluck
Pluck graphql-tag template literals
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): vue-template-compiler is a legitimate optional dependency for Vue SFC support in a GraphQL tag plucking tool; not a malicious addition. | ai | |
| provenance | publisher-changed | AI (provenance): ardatan and dotansimha are both core graphql-toolkit maintainers; this is a documented team transition within the same project, not a suspicious account takeover. | ai | |
| dependencies | unvetted-dep:vue-template-compiler | AI (dependencies): vue-template-compiler is an optional dep used for Vue SFC parsing — legitimate and contextually appropriate for a GraphQL tag pluck utility. | ai | |
| provenance | no-provenance | AI (provenance): Package is 2343 days old with 593 versions; provenance attestation did not exist when this package was established. Not a meaningful risk signal for this package. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 0.10.7 | 5 / 0 | |
| 0.10.6 | 5 / 0 | |
| 0.10.5 | 5 / 0 | |
| 0.10.4 | 5 / 0 | |
| 0.10.3 | 5 / 0 | |
| 0.10.2 | 5 / 0 | |
| 0.10.1 | 5 / 0 | |
| 0.9.12 | 5 / 0 | |
| 0.9.11 | 5 / 0 | |
| 0.9.10 | 5 / 0 | |
| 0.9.9 | 5 / 0 | |
| 0.9.8 | 5 / 0 | |
| 0.9.7 | 5 / 0 | |
| 0.9.6 | 5 / 0 | |
| 0.9.5 | 5 / 0 | |
| 0.9.4 | 4 / 0 | |
| 0.9.3 | 4 / 0 | |
| 0.9.2 | 4 / 0 | |
| 0.9.1 | 3 / 0 | |
| 0.9.0 | 4 / 0 | |
| 0.8.1 | 4 / 0 | |
| 0.8.0 | 4 / 0 | |
| 0.7.5 | 4 / 0 | |
| 0.7.4 | 3 / 0 | |
| 0.7.3 | 3 / 0 | |
| 0.7.2 | 3 / 0 |
v0.10.7
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (dotansimha) than the most recent previously approved version (ardatan) on 2020-05-18, but dotansimha is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.5
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ardatan) than the most recent previously approved version (dotansimha) on 2020-04-24, but ardatan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ardatan) than the most recent previously approved version (dotansimha) on 2020-04-16, but ardatan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (dotansimha) than the most recent previously approved version (ardatan) on 2020-04-07, but dotansimha is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.11
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ardatan) than the most recent previously approved version (dotansimha) on 2020-03-29, but ardatan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ardatan) than the most recent previously approved version (dotansimha) on 2020-03-26, but ardatan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.