@ifc-lite/data
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/generated/epsg-index.generated.js | AI (source-diff): File is a generated EPSG geodetic dataset (long JSON lines), not obfuscated malicious code; pattern is stable for this package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is entirely due to bundling the EPSG coordinate reference system dataset; expected and benign. | ai | |
| provenance | missing-githead | AI (provenance): Likely a CI/publish environment change; no other malicious indicators present. | ai | |
| license | weak-copyleft-license:MPL-2.0 | AI (license): MPL-2.0 is the declared license for this package; stable across all versions. | ai |
Versions (showing 38 of 38)
| Version | Deps | Published |
|---|---|---|
| 2.8.0 | 0 / 4 | |
| 2.7.0 | 0 / 4 | |
| 2.6.0 | 0 / 4 | |
| 1.17.0 | 0 / 2 | |
| 1.15.2 | 0 / 2 | |
| 1.15.1 | 0 / 2 | |
| 1.15.0 | 0 / 2 | |
| 1.14.6 | 0 / 2 | |
| 1.14.5 | 0 / 2 | |
| 1.14.4 | 0 / 2 | |
| 1.14.3 | 0 / 2 | |
| 1.14.2 | 0 / 2 | |
| 1.14.1 | 0 / 2 | |
| 1.14.0 | 0 / 2 | |
| 1.13.0 | 0 / 2 | |
| 1.11.5 | 0 / 2 | |
| 1.11.4 | 0 / 2 | |
| 1.11.3 | 0 / 2 | |
| 1.11.2 | 0 / 2 | |
| 1.11.1 | 0 / 2 | |
| 1.11.0 | 0 / 2 | |
| 1.10.0 | 0 / 2 | |
| 1.9.0 | 0 / 2 | |
| 1.8.0 | 0 / 2 | |
| 1.7.0 | 0 / 2 | |
| 1.6.1 | 0 / 2 | |
| 1.6.0 | 0 / 2 | |
| 1.5.0 | 0 / 2 | |
| 1.3.0 | 0 / 2 | |
| 1.2.1 | 0 / 1 | |
| 1.1.7 | 0 / 1 | |
| 1.1.6 | 0 / 1 | |
| 1.1.4 | 0 / 1 | |
| 1.1.3 | 0 / 1 | |
| 1.1.2 | 0 / 1 | |
| 1.1.1 | 0 / 1 | |
| 1.1.0 | 0 / 1 | |
| 1.0.0 | 0 / 1 |
v2.8.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (louistrue) on 2026-07-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.7.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (louistrue) on unknown date, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.6.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (louistrue) on unknown date, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.