← Home

@ibm-cloud/cloudant

77
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ricelliscloudant-sdks-automation

Keywords

IBMCloudantdatabaseclientSDKofficial

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Legitimate automation account handoff, long-tenured with clean track record. ai
maintainer-change maintainer-removed AI (maintainer-change): Expected removal during org automation transfer, not a takeover. ai
provenance publisher-changed-stale AI (provenance): Stale publisher change 2103d old, consistent with legitimate transfer per rule description. ai
semgrep semgrep:base64-decode AI (semgrep): Decodes Cloudant attachment binary data from API responses; legitimate SDK data handling, not obfuscation. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): @types/node is a type declaration package used implicitly by TypeScript; not a real phantom dep. ai

Versions (showing 77 of 77)

Version Deps Published
0.12.23 2 / 23
0.12.22 2 / 23
0.12.21 2 / 23
0.12.20 2 / 23
0.12.19 2 / 23
0.12.18 2 / 23
0.12.17 2 / 23
0.12.16 2 / 23
0.12.15 2 / 23
0.12.14 2 / 23
0.12.13 2 / 23
0.12.12 2 / 23
0.12.11 2 / 23
0.12.10 2 / 23
0.12.9 2 / 23
0.12.8 2 / 23
0.12.7 2 / 24
0.12.6 2 / 24
0.12.5 2 / 24
0.12.4 2 / 24
0.12.3 2 / 24
0.12.2 2 / 24
0.12.1 2 / 24
0.12.0 2 / 24
0.11.0 2 / 25
0.10.3 2 / 24
0.10.2 2 / 24
0.10.1 2 / 24
0.10.0 2 / 24
0.9.2 2 / 23
0.9.1 2 / 23
0.9.0 2 / 23
0.8.3 2 / 23
0.8.2 2 / 22
0.8.1 2 / 22
0.8.0 2 / 22
0.7.2 2 / 22
0.7.1 2 / 22
0.7.0 2 / 22
0.6.0 2 / 22
0.5.5 2 / 22
0.5.4 2 / 22
0.5.3 2 / 22
0.5.2 2 / 22
0.5.1 2 / 22
0.5.0 2 / 22
0.4.1 2 / 25
0.4.0 2 / 25
0.3.1 2 / 25
0.3.0 2 / 25
0.2.1 2 / 25
0.2.0 2 / 25
0.1.5 2 / 25
0.1.4 2 / 25
0.1.3 2 / 25
0.1.2 2 / 25
0.1.1 2 / 25
0.0.25 4 / 25
0.0.24 4 / 0
0.0.23 4 / 0
0.0.22 4 / 0
0.0.21 4 / 0
0.0.20 4 / 0
0.0.19 4 / 0
0.0.18 3 / 0
0.0.17 3 / 0
0.0.16 3 / 0
0.0.15 3 / 0
0.0.14 3 / 0
0.0.13 3 / 0
0.0.12 3 / 0
0.0.11 3 / 0
0.0.10 3 / 0
0.0.9 3 / 0
0.0.8 3 / 0
0.0.7 3 / 0
0.0.6 3 / 0

v0.12.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-03-13, unremoved on npm for 862d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-03-13. It has since remained available on npm for 862 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.3

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-02-13, unremoved on npm for 891d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-02-13. It has since remained available on npm for 891 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.2

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-01-05, unremoved on npm for 930d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-01-05. It has since remained available on npm for 930 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2024-01-02, unremoved on npm for 933d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2024-01-02. It has since remained available on npm for 933 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-11-21, unremoved on npm for 975d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-11-21. It has since remained available on npm for 975 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-10-31, unremoved on npm for 996d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-10-31. It has since remained available on npm for 996 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-09-28, unremoved on npm for 1029d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-09-28. It has since remained available on npm for 1029 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-09-25, unremoved on npm for 1032d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-09-25. It has since remained available on npm for 1032 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-08-30, unremoved on npm for 1058d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-08-30. It has since remained available on npm for 1058 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-07-13, unremoved on npm for 1106d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-07-13. It has since remained available on npm for 1106 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-06-26, unremoved on npm for 1123d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-06-26. It has since remained available on npm for 1123 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-06-21, unremoved on npm for 1128d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-06-21. It has since remained available on npm for 1128 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-05-24, unremoved on npm for 1156d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-05-24. It has since remained available on npm for 1156 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-04-25, unremoved on npm for 1185d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-04-25. It has since remained available on npm for 1185 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-03-27, unremoved on npm for 1214d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-03-27. It has since remained available on npm for 1214 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-02-09, unremoved on npm for 1260d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-02-09. It has since remained available on npm for 1260 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2023-01-05, unremoved on npm for 1295d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2023-01-05. It has since remained available on npm for 1295 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-11-30, unremoved on npm for 1331d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-11-30. It has since remained available on npm for 1331 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-10-27, unremoved on npm for 1365d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-10-27. It has since remained available on npm for 1365 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-09-30, unremoved on npm for 1392d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-09-30. It has since remained available on npm for 1392 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-08-23, unremoved on npm for 1430d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-08-23. It has since remained available on npm for 1430 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-07-29, unremoved on npm for 1455d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-07-29. It has since remained available on npm for 1455 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-07-06, unremoved on npm for 1478d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-07-06. It has since remained available on npm for 1478 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-05-27, unremoved on npm for 1518d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-05-27. It has since remained available on npm for 1518 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-04-28, unremoved on npm for 1547d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-04-28. It has since remained available on npm for 1547 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-03-29, unremoved on npm for 1577d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-03-29. It has since remained available on npm for 1577 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.25

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-02-16, unremoved on npm for 1619d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-02-16. It has since remained available on npm for 1619 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.24

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2022-01-25, unremoved on npm for 1640d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2022-01-25. It has since remained available on npm for 1640 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.23

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-12-17, unremoved on npm for 1679d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-12-17. It has since remained available on npm for 1679 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.22

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-12-03, unremoved on npm for 1693d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-12-03. It has since remained available on npm for 1693 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.21

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-11-11, unremoved on npm for 1715d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-11-11. It has since remained available on npm for 1715 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.20

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-10-05, unremoved on npm for 1752d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-10-05. It has since remained available on npm for 1752 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.19

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-09-10, unremoved on npm for 1777d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-09-10. It has since remained available on npm for 1777 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.18

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-08-26, unremoved on npm for 1792d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-08-26. It has since remained available on npm for 1792 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.17

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-08-05, unremoved on npm for 1813d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-08-05. It has since remained available on npm for 1813 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.16

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-06-16, unremoved on npm for 1863d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-06-16. It has since remained available on npm for 1863 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.15

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-04-28, unremoved on npm for 1912d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-04-28. It has since remained available on npm for 1912 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.14

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-03-02, unremoved on npm for 1969d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-03-02. It has since remained available on npm for 1969 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.13

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-02-12, unremoved on npm for 1987d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-02-12. It has since remained available on npm for 1987 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.12

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2021-01-12, unremoved on npm for 2018d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2021-01-12. It has since remained available on npm for 2018 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.11

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2020-11-13, unremoved on npm for 2078d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2020-11-13. It has since remained available on npm for 2078 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.10

2 findings
MEDIUM Publisher changed: ricellis → cloudant-sdks-automation (on 2020-10-19, unremoved on npm for 2103d) provenance

This version was published by a different npm account (cloudant-sdks-automation) than the most recent previously approved version (ricellis) on 2020-10-19. It has since remained available on npm for 2103 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.