← Home

@ibm-cloud/cloudant

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ricelliscloudant-sdks-automation

Keywords

IBMCloudantdatabaseclientSDKofficial

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Legitimate automation account handoff, long-tenured with clean track record. ai
maintainer-change maintainer-removed AI (maintainer-change): Expected removal during org automation transfer, not a takeover. ai
provenance publisher-changed-stale AI (provenance): Stale publisher change 2103d old, consistent with legitimate transfer per rule description. ai
semgrep semgrep:base64-decode AI (semgrep): Decodes Cloudant attachment binary data from API responses; legitimate SDK data handling, not obfuscation. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): @types/node is a type declaration package used implicitly by TypeScript; not a real phantom dep. ai

Versions (showing 51 of 77)

View all versions
Version Deps Published
0.12.23 2 / 23
0.12.22 2 / 23
0.12.21 2 / 23
0.12.20 2 / 23
0.12.19 2 / 23
0.12.18 2 / 23
0.12.17 2 / 23
0.12.16 2 / 23
0.12.15 2 / 23
0.12.14 2 / 23
0.12.13 2 / 23
0.12.12 2 / 23
0.12.11 2 / 23
0.12.10 2 / 23
0.12.9 2 / 23
0.12.8 2 / 23
0.12.7 2 / 24
0.12.6 2 / 24
0.12.5 2 / 24
0.12.4 2 / 24
0.12.3 2 / 24
0.12.2 2 / 24
0.12.1 2 / 24
0.12.0 2 / 24
0.11.0 2 / 25
0.10.3 2 / 24
0.10.2 2 / 24
0.10.1 2 / 24
0.10.0 2 / 24
0.9.2 2 / 23
0.9.1 2 / 23
0.9.0 2 / 23
0.8.3 2 / 23
0.8.2 2 / 22
0.8.1 2 / 22
0.8.0 2 / 22
0.7.2 2 / 22
0.7.1 2 / 22
0.7.0 2 / 22
0.6.0 2 / 22
0.5.5 2 / 22
0.5.4 2 / 22
0.5.3 2 / 22
0.5.2 2 / 22
0.5.1 2 / 22
0.5.0 2 / 22
0.4.1 2 / 25
0.4.0 2 / 25
0.3.1 2 / 25
0.3.0 2 / 25
0.2.1 2 / 25

v0.12.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-03-13, unremoved on npm for 862d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-03-13. It has since remained available on npm for 862 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.3

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-02-13, unremoved on npm for 891d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-02-13. It has since remained available on npm for 891 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.2

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-01-05, unremoved on npm for 930d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-01-05. It has since remained available on npm for 930 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-01-02, unremoved on npm for 933d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-01-02. It has since remained available on npm for 933 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-11-21, unremoved on npm for 975d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-11-21. It has since remained available on npm for 975 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-10-31, unremoved on npm for 996d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-10-31. It has since remained available on npm for 996 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-09-28, unremoved on npm for 1029d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-09-28. It has since remained available on npm for 1029 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-09-25, unremoved on npm for 1032d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-09-25. It has since remained available on npm for 1032 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-08-30, unremoved on npm for 1058d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-08-30. It has since remained available on npm for 1058 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-07-13, unremoved on npm for 1106d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-07-13. It has since remained available on npm for 1106 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-06-26, unremoved on npm for 1123d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-06-26. It has since remained available on npm for 1123 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-06-21, unremoved on npm for 1128d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-06-21. It has since remained available on npm for 1128 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-05-24, unremoved on npm for 1156d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-05-24. It has since remained available on npm for 1156 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-04-25, unremoved on npm for 1185d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-04-25. It has since remained available on npm for 1185 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-03-27, unremoved on npm for 1214d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-03-27. It has since remained available on npm for 1214 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-02-09, unremoved on npm for 1260d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-02-09. It has since remained available on npm for 1260 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-01-05, unremoved on npm for 1295d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-01-05. It has since remained available on npm for 1295 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-11-30, unremoved on npm for 1331d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-11-30. It has since remained available on npm for 1331 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-10-27, unremoved on npm for 1365d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-10-27. It has since remained available on npm for 1365 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-09-30, unremoved on npm for 1392d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-09-30. It has since remained available on npm for 1392 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.