@heliofi/launchpad-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Known maintainer resuming publishing; no malicious payload in diff. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer matches existing known name per provenance info. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): buffer is a standard well-known polyfill, not a supply-chain risk. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Config-only reference, consistent with monorepo shared package pattern. | ai |
Versions (showing 51 of 118)
| Version | Deps | Published |
|---|---|---|
| 1.7.40 | 8 / 6 | |
| 1.7.39 | 8 / 6 | |
| 1.7.37 | 8 / 6 | |
| 1.7.36 | 8 / 6 | |
| 1.7.35 | 8 / 6 | |
| 1.7.34 | 8 / 6 | |
| 1.7.33 | 8 / 6 | |
| 1.7.32 | 8 / 6 | |
| 1.7.31 | 8 / 6 | |
| 1.7.30 | 8 / 6 | |
| 1.7.29 | 8 / 6 | |
| 1.7.28 | 8 / 6 | |
| 1.7.27 | 8 / 6 | |
| 1.7.26 | 8 / 6 | |
| 1.7.25 | 7 / 5 | |
| 1.7.24 | 7 / 5 | |
| 1.7.23 | 7 / 5 | |
| 1.7.22 | 7 / 5 | |
| 1.7.21 | 7 / 5 | |
| 1.7.20 | 7 / 5 | |
| 1.7.19 | 7 / 5 | |
| 1.7.18 | 7 / 5 | |
| 1.7.17 | 7 / 5 | |
| 1.7.16 | 7 / 5 | |
| 1.7.15 | 7 / 5 | |
| 1.7.14 | 7 / 5 | |
| 1.7.12 | 7 / 5 | |
| 1.7.11 | 7 / 5 | |
| 1.7.10 | 7 / 5 | |
| 1.7.9 | 7 / 5 | |
| 1.7.8 | 7 / 5 | |
| 1.7.7 | 7 / 5 | |
| 1.7.6 | 7 / 5 | |
| 1.7.5 | 7 / 5 | |
| 1.7.4 | 7 / 5 | |
| 1.7.3 | 7 / 5 | |
| 1.7.2 | 7 / 5 | |
| 1.7.1 | 7 / 5 | |
| 1.6.54 | 7 / 5 | |
| 1.6.53 | 7 / 5 | |
| 1.6.52 | 7 / 5 | |
| 1.6.51 | 7 / 5 | |
| 1.6.50 | 7 / 5 | |
| 1.6.49 | 7 / 5 | |
| 1.6.48 | 7 / 5 | |
| 1.6.47 | 7 / 5 | |
| 1.6.46 | 7 / 5 | |
| 1.6.45 | 7 / 5 | |
| 1.6.44 | 7 / 5 | |
| 1.6.43 | 7 / 5 | |
| 1.6.42 | 7 / 5 |
v1.7.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.36
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-11-17, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.35
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-11-07, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.33
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-10-15, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.32
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-10-13, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.31
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-10-13, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.30
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-10-03, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.28
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-09-25, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.27
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-09-08, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.26
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-08-28, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.24
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-08-05, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.21
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (martinavagyan) on 2025-08-05, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.20
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (martinavagyan) on 2025-08-01, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (hhenryhharris) on 2025-07-30, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.18
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (hhenryhharris) on 2025-07-30, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (xyz1hang) on 2025-07-29, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (tigran-helio) on 2025-07-25, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (tigran-helio) on 2025-07-21, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tigran-helio) than the most recent previously approved version (hhenryhharris) on 2025-07-17, but tigran-helio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tigran-helio) than the most recent previously approved version (hhenryhharris) on 2025-07-09, but tigran-helio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (xyz1hang) on 2025-07-03, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (xyz1hang) on 2025-06-26, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-18, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (bartoszlhelio) on 2025-06-18, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (xyz1hang) on 2025-06-17, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.53
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-12, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.52
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-12, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.51
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (xyz1hang) on 2025-06-12, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.50
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (xyz1hang) on 2025-06-12, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.49
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.47
2 findingsThis version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-03. It has since remained available on npm for 411 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.45
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (00mb) on 2025-05-30, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.44
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (00mb) on 2025-05-19, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.42
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (00mb) on 2025-05-14, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.