@hed-hog/tag
```markdown # @hed-hog/tag
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @hed-hog/tag is a scoped monorepo package; Levenshtein distance to 'pg' is not a credible typosquat signal here. | ai | |
| phantom-deps | phantom-dep:@hed-hog/core | AI (phantom-deps): Same org scope; peer/config-only usage in monorepo is expected. | ai | |
| phantom-deps | phantom-dep:@nestjs/core | AI (phantom-deps): NestJS framework peer dep referenced in config; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@nestjs/jwt | AI (phantom-deps): NestJS peer dep referenced in config files; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:@nestjs/config | AI (phantom-deps): NestJS peer dep referenced in config files; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:@nestjs/mapped-types | AI (phantom-deps): NestJS peer dep referenced in config files; phantom-dep false positive for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 0.0.364 | 10 / 0 | |
| 0.0.361 | 10 / 0 | |
| 0.0.358 | 10 / 0 | |
| 0.0.355 | 10 / 0 | |
| 0.0.354 | 10 / 0 | |
| 0.0.353 | 10 / 0 | |
| 0.0.351 | 10 / 0 | |
| 0.0.350 | 10 / 0 | |
| 0.0.349 | 10 / 0 | |
| 0.0.347 | 10 / 0 | |
| 0.0.338 | 10 / 0 | |
| 0.0.332 | 10 / 0 | |
| 0.0.331 | 10 / 0 | |
| 0.0.330 | 10 / 0 | |
| 0.0.329 | 10 / 0 | |
| 0.0.328 | 10 / 0 | |
| 0.0.327 | 10 / 0 | |
| 0.0.326 | 10 / 0 | |
| 0.0.325 | 10 / 0 | |
| 0.0.322 | 10 / 0 | |
| 0.0.321 | 10 / 0 | |
| 0.0.319 | 10 / 0 | |
| 0.0.318 | 10 / 0 | |
| 0.0.317 | 10 / 0 | |
| 0.0.316 | 10 / 0 | |
| 0.0.315 | 10 / 0 | |
| 0.0.314 | 10 / 0 | |
| 0.0.312 | 10 / 0 | |
| 0.0.311 | 10 / 0 | |
| 0.0.310 | 10 / 0 | |
| 0.0.309 | 10 / 0 | |
| 0.0.306 | 10 / 0 |
v0.0.364
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.361
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.358
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.355
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.354
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.353
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.351
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.350
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.349
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.347
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.338
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.332
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.331
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.330
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.329
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.328
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.327
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.326
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.325
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.322
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.321
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.319
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.318
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.317
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.316
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.315
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.314
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.312
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.311
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.310
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.309
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.