← Home

@hashgraph/sdk

71
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

steven.sheehyswirldslabs-adminrbair23nathan-swirldslabshedera-eng-automationnana-ec

Keywords

hierohederahashgraphsdktransactions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff bulk-obfuscated-files:lib AI (source-diff): Babel-compiled lib/ output; hex blob is embedded address-book protobuf data, benign. ai
phantom-deps phantom-dep:@types/utf8 AI (phantom-deps): Type-only package, loaded by convention. ai
npm-metadata url-dep:@hashgraph/cryptography AI (npm-metadata): Lerna monorepo sibling package reference, standard for this SDK's structure. ai
phantom-deps phantom-dep:@types/crypto-js AI (phantom-deps): Type-only package, loaded by convention. ai
source-diff large-new-source-files AI (source-diff): Minified lib/ build output shipped alongside src/; benign for this SDK. ai
source-diff encoded-string-file:lib/address_book/AddressBooks.cjs AI (source-diff): Hex-encoded protobuf NodeAddressBook data for mainnet/testnet/previewnet; expected for this SDK. ai
source-diff obfuscated-file:lib/network/AddressBookQueryWeb.js AI (source-diff): Browser-targeted minified bundle mapped in package.json browser field; standard build output for this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/previewnet.d.ts AI (source-diff): Type declaration includes address book constant; expected for this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/mainnet.d.ts AI (source-diff): Type declaration includes address book constant; expected for this SDK. ai
source-diff encoded-string-file:dist/umd.js AI (source-diff): UMD bundle includes the same protobuf-encoded address book data; expected bundled artifact. ai
source-diff encoded-string-file:lib/client/addressbooks/testnet.d.ts AI (source-diff): Type declaration includes address book constant; expected for this SDK. ai
source-diff encoded-string-file:dist/umd.min.js AI (source-diff): Minified UMD bundle includes the same protobuf-encoded address book data; expected bundled artifact. ai
source-diff encoded-string-file:lib/client/addressbooks/previewnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/mainnet.cjs AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/previewnet.cjs AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/testnet.cjs AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/mainnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:src/client/addressbooks/mainnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera mainnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:src/client/addressbooks/previewnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera previewnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:lib/client/addressbooks/testnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. ai
source-diff encoded-string-file:src/client/addressbooks/testnet.js AI (source-diff): Hex-encoded protobuf address book data for Hedera testnet nodes; stable pattern in this SDK. ai
dependencies unvetted-dep:@hashgraph/proto AI (dependencies): First-party Hedera/Hiero protobuf definitions package; expected dependency for this SDK. ai
dependencies unvetted-dep:protobufjs AI (dependencies): protobufjs is a well-known, widely-used protobuf library; its use in a blockchain SDK is expected and legitimate. ai
dependencies unvetted-dep:@hashgraph/cryptography AI (dependencies): First-party Hedera/Hiero cryptography package; expected dependency for this SDK. ai
phantom-deps phantom-dep:ansi-styles AI (phantom-deps): ansi-styles is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:strip-ansi AI (phantom-deps): strip-ansi is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:ansi-regex AI (phantom-deps): ansi-regex is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:debug AI (phantom-deps): debug is declared as a direct dependency; phantom detection is a false positive for this package's build/import structure. ai
semgrep semgrep:hex-decode AI (semgrep): Buffer.from(str, 'hex') is standard Node.js hex decoding, expected and necessary in a blockchain SDK for handling keys, addresses, and transaction data. ai
phantom-deps phantom-dep:bn.js AI (phantom-deps): bn.js is declared as a peerDependency and in resolutions; phantom detection is a false positive for this package's build structure. ai
phantom-deps phantom-dep:@ethersproject/bignumber AI (phantom-deps): @ethersproject/bignumber is declared as a direct dependency; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): pino-pretty is declared as a direct dependency; phantom detection is a false positive for this package. ai

Versions (showing 71 of 71)

Version Deps Published
2.81.0 21 / 56
2.80.0 21 / 54
2.79.0 21 / 54
2.78.0 21 / 54
2.77.0 21 / 54
2.76.0 21 / 54
2.75.0 21 / 54
2.74.0 21 / 54
2.73.2 21 / 54
2.73.1 21 / 54
2.72.0 17 / 54
2.71.1 17 / 54
2.71.0 17 / 54
2.70.0 17 / 54
2.69.0 17 / 54
2.68.0 17 / 53
2.67.0 17 / 53
2.66.0 17 / 53
2.65.1 17 / 53
2.65.0 17 / 53
2.64.5 17 / 53
2.64.3 17 / 53
2.62.0 17 / 53
2.61.0 17 / 50
2.59.0 18 / 48
2.58.0 18 / 48
2.57.2 18 / 48
2.56.0 18 / 48
2.55.1 18 / 48
2.55.0 18 / 48
2.54.2 18 / 49
2.53.0 18 / 49
2.52.0 18 / 49
2.51.0 18 / 49
2.50.0 18 / 49
2.49.2 18 / 49
2.48.1 18 / 49
2.48.0 18 / 49
2.47.0 18 / 49
2.46.0 18 / 49
2.45.0 18 / 48
2.2.0 9 / 39
2.0.28 11 / 36
2.0.27 11 / 36
2.0.26 11 / 36
2.0.25 11 / 36
2.0.24 11 / 36
2.0.23 11 / 36
2.0.22 11 / 36
2.0.21 11 / 36
2.0.20 11 / 36
2.0.19 10 / 36
2.0.18 10 / 36
2.0.17 5 / 36
2.0.16 5 / 36
2.0.15 5 / 36
2.0.14 5 / 36
2.0.13 5 / 36
2.0.12 5 / 36
2.0.11 5 / 36
2.0.10 5 / 36
2.0.9 5 / 36
2.0.8 5 / 36
2.0.7 5 / 36
2.0.6 5 / 36
2.0.5 5 / 36
2.0.4 5 / 36
2.0.3 5 / 36
2.0.2 5 / 36
2.0.1 5 / 36
2.0.0 5 / 36

v2.62.0

20 findings
HIGH New obfuscated file: lib/token/AbstractTokenTransferTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceAdjustTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceApproveTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountId.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountInfo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/address_book/AddressBooks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/browser.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/Cache.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/client/Client.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/constants/ClientConstants.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCallQuery.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionParameters.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionResult.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionSelector.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.61.0

20 findings
HIGH New obfuscated file: lib/token/AbstractTokenTransferTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceAdjustTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountAllowanceApproveTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountId.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountInfo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/account/AccountUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/address_book/AddressBooks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/browser.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/Cache.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/client/Client.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/constants/ClientConstants.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCallQuery.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractCreateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionParameters.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionResult.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractFunctionSelector.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/contract/ContractUpdateTransaction.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.59.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.58.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.57.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.56.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.55.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.55.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.54.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.53.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.52.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.51.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.49.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.48.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.47.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danielakhterov.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.28

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danielakhterov.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: danielakhterov → mehcode (on 2020-12-23, known maintainer) provenance

This version was published by a different npm account (mehcode) than the most recent previously approved version (danielakhterov) on 2020-12-23, but mehcode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mehcode → danielakhterov (on 2020-12-09, known maintainer) provenance

This version was published by a different npm account (danielakhterov) than the most recent previously approved version (mehcode) on 2020-12-09, but danielakhterov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.0.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mehcode → danielakhterov (on 2020-12-02, known maintainer) provenance

This version was published by a different npm account (danielakhterov) than the most recent previously approved version (mehcode) on 2020-12-02, but danielakhterov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.0.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: danielakhterov → mehcode (on 2020-12-01, known maintainer) provenance

This version was published by a different npm account (mehcode) than the most recent previously approved version (danielakhterov) on 2020-12-01, but mehcode is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.