@heliofi/launchpad-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Known maintainer resuming publishing; no malicious payload in diff. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer matches existing known name per provenance info. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): buffer is a standard well-known polyfill, not a supply-chain risk. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Config-only reference, consistent with monorepo shared package pattern. | ai |
Versions (showing 100 of 118)
| Version | Deps | Published |
|---|---|---|
| 1.7.40 | 8 / 6 | |
| 1.7.39 | 8 / 6 | |
| 1.7.37 | 8 / 6 | |
| 1.7.36 | 8 / 6 | |
| 1.7.35 | 8 / 6 | |
| 1.7.34 | 8 / 6 | |
| 1.7.33 | 8 / 6 | |
| 1.7.32 | 8 / 6 | |
| 1.7.31 | 8 / 6 | |
| 1.7.30 | 8 / 6 | |
| 1.7.29 | 8 / 6 | |
| 1.7.28 | 8 / 6 | |
| 1.7.27 | 8 / 6 | |
| 1.7.26 | 8 / 6 | |
| 1.7.25 | 7 / 5 | |
| 1.7.24 | 7 / 5 | |
| 1.7.23 | 7 / 5 | |
| 1.7.22 | 7 / 5 | |
| 1.7.21 | 7 / 5 | |
| 1.7.20 | 7 / 5 | |
| 1.7.19 | 7 / 5 | |
| 1.7.18 | 7 / 5 | |
| 1.7.17 | 7 / 5 | |
| 1.7.16 | 7 / 5 | |
| 1.7.15 | 7 / 5 | |
| 1.7.14 | 7 / 5 | |
| 1.7.12 | 7 / 5 | |
| 1.7.11 | 7 / 5 | |
| 1.7.10 | 7 / 5 | |
| 1.7.9 | 7 / 5 | |
| 1.7.8 | 7 / 5 | |
| 1.7.7 | 7 / 5 | |
| 1.7.6 | 7 / 5 | |
| 1.7.5 | 7 / 5 | |
| 1.7.4 | 7 / 5 | |
| 1.7.3 | 7 / 5 | |
| 1.7.2 | 7 / 5 | |
| 1.7.1 | 7 / 5 | |
| 1.6.54 | 7 / 5 | |
| 1.6.53 | 7 / 5 | |
| 1.6.52 | 7 / 5 | |
| 1.6.51 | 7 / 5 | |
| 1.6.50 | 7 / 5 | |
| 1.6.49 | 7 / 5 | |
| 1.6.48 | 7 / 5 | |
| 1.6.47 | 7 / 5 | |
| 1.6.46 | 7 / 5 | |
| 1.6.45 | 7 / 5 | |
| 1.6.44 | 7 / 5 | |
| 1.6.43 | 7 / 5 | |
| 1.6.42 | 7 / 5 | |
| 1.6.41 | 7 / 5 | |
| 1.6.39 | 7 / 5 | |
| 1.6.38 | 7 / 5 | |
| 1.6.37 | 7 / 5 | |
| 1.6.36 | 7 / 5 | |
| 1.6.35 | 7 / 5 | |
| 1.6.34 | 7 / 5 | |
| 1.6.33 | 7 / 5 | |
| 1.6.32 | 7 / 5 | |
| 1.6.31 | 7 / 5 | |
| 1.6.30 | 7 / 5 | |
| 1.6.29 | 7 / 5 | |
| 1.6.28 | 7 / 5 | |
| 1.6.27 | 7 / 5 | |
| 1.6.26 | 7 / 5 | |
| 1.6.25 | 7 / 5 | |
| 1.6.24 | 7 / 4 | |
| 1.6.23 | 7 / 4 | |
| 1.6.22 | 7 / 4 | |
| 1.6.21 | 6 / 4 | |
| 1.6.20 | 6 / 4 | |
| 1.6.19 | 6 / 4 | |
| 1.6.18 | 6 / 4 | |
| 1.6.17 | 6 / 4 | |
| 1.6.16 | 6 / 4 | |
| 1.6.15 | 6 / 4 | |
| 1.6.14 | 7 / 4 | |
| 1.6.11 | 7 / 4 | |
| 1.6.10 | 7 / 4 | |
| 1.6.9 | 7 / 4 | |
| 1.6.8 | 7 / 4 | |
| 1.6.6 | 7 / 4 | |
| 1.6.5 | 7 / 4 | |
| 1.6.4 | 7 / 4 | |
| 1.6.3 | 7 / 4 | |
| 1.6.1 | 7 / 4 | |
| 1.5.9 | 7 / 4 | |
| 1.5.8 | 6 / 4 | |
| 1.5.7 | 6 / 4 | |
| 1.5.6 | 6 / 4 | |
| 1.5.5 | 6 / 4 | |
| 1.5.3 | 6 / 4 | |
| 1.5.1 | 6 / 4 | |
| 1.5.0 | 6 / 4 | |
| 1.4.0 | 6 / 4 | |
| 1.3.8 | 6 / 4 | |
| 1.3.7 | 6 / 4 | |
| 1.3.6 | 6 / 4 | |
| 1.3.5 | 6 / 4 |
v1.7.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.36
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-11-17, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.35
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-11-07, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.33
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-10-15, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.32
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-10-13, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.31
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-10-13, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.30
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-10-03, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.28
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-09-25, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.27
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-09-08, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.26
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-08-28, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.24
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (hhenryhharris) on 2025-08-05, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.21
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (martinavagyan) on 2025-08-05, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.20
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (martinavagyan) on 2025-08-01, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (hhenryhharris) on 2025-07-30, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.18
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (hhenryhharris) on 2025-07-30, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (xyz1hang) on 2025-07-29, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (tigran-helio) on 2025-07-25, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (tigran-helio) on 2025-07-21, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tigran-helio) than the most recent previously approved version (hhenryhharris) on 2025-07-17, but tigran-helio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tigran-helio) than the most recent previously approved version (hhenryhharris) on 2025-07-09, but tigran-helio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (xyz1hang) on 2025-07-03, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (xyz1hang) on 2025-06-26, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-18, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (bartoszlhelio) on 2025-06-18, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (xyz1hang) on 2025-06-17, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.53
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-12, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.52
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-12, but xyz1hang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.51
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (xyz1hang) on 2025-06-12, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.50
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (xyz1hang) on 2025-06-12, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.49
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.47
2 findingsThis version was published by a different npm account (xyz1hang) than the most recent previously approved version (bartoszlhelio) on 2025-06-03. It has since remained available on npm for 411 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.45
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (00mb) on 2025-05-30, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.44
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (00mb) on 2025-05-19, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.42
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (00mb) on 2025-05-14, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.38
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (00mb) than the most recent previously approved version (bartoszlhelio) on 2025-05-02, but 00mb is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.37
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (a2048) on 2025-04-30, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.36
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (a2048) than the most recent previously approved version (hhenryhharris) on 2025-04-25, but a2048 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.35
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (martinavagyan) on 2025-04-23, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.34
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (hhenryhharris) on 2025-04-17, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.33
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (bartoszlhelio) on 2025-04-17, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.28
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-04-08, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.26
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (bartoszlhelio) on 2025-04-01, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.25
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-03-27, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.24
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (bartoszlhelio) on 2025-03-27, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.23
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (a2048) on 2025-03-27, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.22
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (a2048) than the most recent previously approved version (bartoszlhelio) on 2025-03-26, but a2048 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (martinavagyan) on 2025-03-14, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (hhenryhharris) on 2025-03-03, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (bartoszlhelio) on 2025-02-27, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (hhenryhharris) on 2025-02-26, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (martinavagyan) on 2025-02-25, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (bartoszlhelio) on 2025-02-20, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (martinavagyan) on 2025-02-20, but bartoszlhelio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (martinavagyan) than the most recent previously approved version (hhenryhharris) on 2025-02-18, but martinavagyan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (ib1) on 2025-02-07, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ib1) than the most recent previously approved version (bartoszlhelio) on 2025-02-06, but ib1 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.5
2 findingsThis version was published by a different npm account (bartoszlhelio) than the most recent previously approved version (ib1) on 2025-01-22. It has since remained available on npm for 542 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ib1) than the most recent previously approved version (00mb) on 2025-01-22, but ib1 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (00mb) than the most recent previously approved version (hhenryhharris) on 2025-01-16, but 00mb is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hhenryhharris) than the most recent previously approved version (ib1) on 2025-01-06, but hhenryhharris is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.