@hey-api/client-fetch
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): tsup-bundled minified output, not obfuscation; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): tsup-bundled minified output, not obfuscation; benign build artifact. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): mrlubos is a known maintainer on prior approved versions (email match); legitimate publish, not takeover. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established 1.5M-dl client library; no-deps and README heuristic are false positives. | ai |
Versions (showing 51 of 56)
| Version | Deps | Published |
|---|---|---|
| 0.13.1 | 0 / 3 | |
| 0.13.0 | 0 / 3 | |
| 0.12.0 | 0 / 3 | |
| 0.11.0 | 0 / 3 | |
| 0.10.2 | 0 / 3 | |
| 0.10.1 | 0 / 3 | |
| 0.10.0 | 0 / 2 | |
| 0.9.0 | 0 / 2 | |
| 0.8.4 | 0 / 1 | |
| 0.8.3 | 0 / 1 | |
| 0.8.2 | 0 / 1 | |
| 0.8.1 | 0 / 1 | |
| 0.8.0 | 0 / 1 | |
| 0.7.3 | 0 / 1 | |
| 0.7.2 | 0 / 1 | |
| 0.7.1 | 0 / 1 | |
| 0.7.0 | 0 / 0 | |
| 0.6.0 | 0 / 0 | |
| 0.5.7 | 0 / 0 | |
| 0.5.6 | 0 / 0 | |
| 0.5.5 | 0 / 0 | |
| 0.5.4 | 0 / 0 | |
| 0.5.3 | 0 / 0 | |
| 0.5.2 | 0 / 0 | |
| 0.5.1 | 0 / 0 | |
| 0.5.0 | 0 / 0 | |
| 0.4.4 | 0 / 0 | |
| 0.4.3 | 0 / 0 | |
| 0.4.2 | 0 / 0 | |
| 0.4.1 | 0 / 0 | |
| 0.4.0 | 0 / 0 | |
| 0.3.4 | 0 / 0 | |
| 0.3.3 | 0 / 0 | |
| 0.3.2 | 0 / 0 | |
| 0.3.1 | 0 / 0 | |
| 0.3.0 | 0 / 0 | |
| 0.2.4 | 0 / 0 | |
| 0.2.3 | 0 / 0 | |
| 0.2.2 | 0 / 0 | |
| 0.2.1 | 0 / 0 | |
| 0.2.0 | 0 / 0 | |
| 0.1.14 | 0 / 0 | |
| 0.1.13 | 0 / 0 | |
| 0.1.12 | 0 / 0 | |
| 0.1.11 | 0 / 0 | |
| 0.1.10 | 0 / 0 | |
| 0.1.9 | 0 / 0 | |
| 0.1.8 | 0 / 0 | |
| 0.1.7 | 0 / 0 | |
| 0.1.6 | 0 / 0 | |
| 0.1.5 | 0 / 0 |
v0.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.2
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-02-27, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.1
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-02-05, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.0
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-02-02, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.3
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-01-30, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.2
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-01-27, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.1
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-01-21, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.0
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-01-14, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.0
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2025-01-06, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.7
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-12-19, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.6
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-12-18, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.5
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-12-17, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.4
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-12-12, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.3
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-12-12, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.2
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-12-06, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.1
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-12-05, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.0
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-11-25, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.4
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-11-18, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.3
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-11-10, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.2
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-10-13, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.1
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-10-11, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.0
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-09-27, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.4
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-09-26, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.3
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-09-25, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.2
5 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-09-22, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.1
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-09-19, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.0
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-09-17, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.2.4
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-08-12, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.2.3
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-08-10, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.2.2
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-08-07, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.2.1
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-08-06, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.2.0
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-08-01, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.14
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-08-01, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.13
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-07-31, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.12
3 findingsAll previous maintainers (lmenus) were replaced by new maintainers (mrlubos). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mrlubos) than the most recent previously approved version (lmenus) on 2024-07-26, but mrlubos is listed as a maintainer on prior approved versions (matched on email). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.