@inkeep/agents-run-api
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/dbClient.cjs | AI (source-diff): DB client bundle; network+exec pattern is drizzle/pglite internals, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dbClient.js | AI (source-diff): Bundled pglite/drizzle build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dbClient.cjs | AI (source-diff): Bundled pglite/drizzle build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dbClient.js | AI (source-diff): DB client bundle; network+exec pattern is drizzle/pglite internals, not a dropper. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps match package.json's declared expanded feature set. | ai | |
| source-diff | net-exec-file:dist/chunk-V4RNZ6BX.js | AI (source-diff): Bundled pglite/drizzle DB chunk, not injected dropper code. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Org-level CI/CD publisher transition, not a takeover; provenance unchanged/improved. | ai | |
| source-diff | net-exec-file:dist/chunk-D3AB2AZW.js | AI (source-diff): Bundled pglite/drizzle chunk, not a loader; standard build output. | ai | |
| source-diff | net-exec-file:dist/chunk-EVOISBFH.js | AI (source-diff): 418KB file is bundled @electric-sql/pglite WASM/Emscripten runtime; eval/spawn are its internals, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-W6UIBREL.js | AI (source-diff): Bundled pglite/drizzle DB code, not a network dropper; no exfil or fetched-binary behavior in sample. | ai | |
| phantom-deps | phantom-dep:jose | AI (phantom-deps): Used in config/runtime, false-positive pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/semantic-conventions | AI (phantom-deps): Declared dependency used transitively in monorepo; stable false positive. | ai | |
| phantom-deps | phantom-dep:@hono/otel | AI (phantom-deps): Declared dependency used transitively in monorepo; stable false positive. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): Declared dependency used transitively in monorepo; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-metrics | AI (phantom-deps): Declared dependency used transitively in monorepo; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-jaeger | AI (phantom-deps): Declared dependency used transitively in monorepo; stable false positive. | ai | |
| phantom-deps | phantom-dep:keytar | AI (phantom-deps): Credential storage; used indirectly in auth flow. | ai | |
| phantom-deps | phantom-dep:drizzle-orm | AI (phantom-deps): ORM dependency; used indirectly. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Config validation dependency; legitimately used indirectly. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): Used via config/instrumentation, not a direct import; benign for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-trace-node | AI (phantom-deps): Config-file usage; OTel setup pattern. | ai | |
| phantom-deps | phantom-dep:json-schema-to-zod | AI (phantom-deps): Config-file usage. | ai | |
| phantom-deps | phantom-dep:@hono/node-server | AI (phantom-deps): Config-file usage. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/react | AI (phantom-deps): Config-file usage. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): Config-file usage. | ai | |
| phantom-deps | phantom-dep:ts-pattern | AI (phantom-deps): Config-file usage. | ai | |
| phantom-deps | phantom-dep:exit-hook | AI (phantom-deps): Config-file usage. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): Config-file usage. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Config-file usage; standard env loader. | ai |
Versions (showing 100 of 168)
| Version | Deps | Published |
|---|---|---|
| 0.41.2 | 29 / 11 | |
| 0.41.1 | 29 / 11 | |
| 0.41.0 | 29 / 11 | |
| 0.40.0 | 29 / 11 | |
| 0.39.4 | 40 / 15 | |
| 0.39.3 | 40 / 15 | |
| 0.39.2 | 40 / 15 | |
| 0.39.1 | 40 / 15 | |
| 0.39.0 | 40 / 15 | |
| 0.38.3 | 40 / 15 | |
| 0.38.2 | 40 / 15 | |
| 0.38.1 | 40 / 15 | |
| 0.38.0 | 40 / 15 | |
| 0.37.2 | 40 / 15 | |
| 0.37.1 | 42 / 15 | |
| 0.37.0 | 42 / 15 | |
| 0.36.1 | 41 / 15 | |
| 0.36.0 | 41 / 15 | |
| 0.35.12 | 41 / 15 | |
| 0.35.11 | 1 / 16 | |
| 0.35.10 | 41 / 15 | |
| 0.35.9 | 41 / 15 | |
| 0.35.8 | 41 / 15 | |
| 0.35.7 | 41 / 15 | |
| 0.35.6 | 41 / 15 | |
| 0.35.5 | 41 / 15 | |
| 0.35.4 | 41 / 15 | |
| 0.35.3 | 41 / 15 | |
| 0.35.2 | 41 / 15 | |
| 0.35.1 | 41 / 15 | |
| 0.35.0 | 41 / 15 | |
| 0.34.1 | 41 / 15 | |
| 0.34.0 | 41 / 15 | |
| 0.33.2 | 40 / 15 | |
| 0.33.1 | 40 / 15 | |
| 0.33.0 | 40 / 15 | |
| 0.32.2 | 40 / 15 | |
| 0.32.1 | 40 / 15 | |
| 0.32.0 | 40 / 15 | |
| 0.31.7 | 40 / 14 | |
| 0.31.6 | 40 / 14 | |
| 0.31.5 | 40 / 14 | |
| 0.31.4 | 40 / 14 | |
| 0.31.3 | 40 / 14 | |
| 0.31.2 | 39 / 14 | |
| 0.31.1 | 39 / 14 | |
| 0.31.0 | 39 / 14 | |
| 0.30.4 | 39 / 14 | |
| 0.30.3 | 39 / 14 | |
| 0.30.2 | 39 / 14 | |
| 0.30.1 | 39 / 14 | |
| 0.30.0 | 39 / 14 | |
| 0.29.11 | 39 / 14 | |
| 0.29.10 | 39 / 14 | |
| 0.29.9 | 39 / 14 | |
| 0.29.8 | 39 / 14 | |
| 0.29.7 | 39 / 14 | |
| 0.29.6 | 39 / 14 | |
| 0.29.5 | 39 / 14 | |
| 0.29.4 | 39 / 14 | |
| 0.29.3 | 39 / 14 | |
| 0.29.2 | 39 / 14 | |
| 0.29.1 | 39 / 14 | |
| 0.29.0 | 39 / 14 | |
| 0.28.0 | 39 / 14 | |
| 0.27.0 | 39 / 14 | |
| 0.26.2 | 39 / 14 | |
| 0.26.1 | 39 / 14 | |
| 0.26.0 | 39 / 14 | |
| 0.25.0 | 39 / 14 | |
| 0.24.2 | 39 / 14 | |
| 0.24.1 | 39 / 14 | |
| 0.24.0 | 39 / 14 | |
| 0.23.5 | 39 / 14 | |
| 0.23.4 | 39 / 14 | |
| 0.23.3 | 39 / 14 | |
| 0.23.2 | 39 / 14 | |
| 0.23.1 | 39 / 14 | |
| 0.23.0 | 39 / 14 | |
| 0.22.12 | 39 / 14 | |
| 0.22.11 | 39 / 14 | |
| 0.22.9 | 39 / 14 | |
| 0.22.8 | 39 / 14 | |
| 0.22.7 | 39 / 14 | |
| 0.22.6 | 39 / 14 | |
| 0.22.5 | 39 / 14 | |
| 0.22.4 | 39 / 14 | |
| 0.22.3 | 39 / 14 | |
| 0.22.2 | 39 / 14 | |
| 0.22.1 | 39 / 14 | |
| 0.22.0 | 38 / 14 | |
| 0.21.1 | 38 / 14 | |
| 0.21.0 | 38 / 14 | |
| 0.20.1 | 38 / 14 | |
| 0.20.0 | 38 / 14 | |
| 0.19.9 | 38 / 14 | |
| 0.19.8 | 38 / 14 | |
| 0.19.7 | 38 / 14 | |
| 0.19.6 | 38 / 14 | |
| 0.19.5 | 38 / 14 |
v0.41.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.41.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.41.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2026-01-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.40.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2026-01-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.39.4
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.39.3
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.39.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.39.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.39.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.38.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.38.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.38.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.38.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abraham-inkeep) on 2025-12-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.37.2
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.35.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.34.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.34.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.33.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.33.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.33.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.32.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.32.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.32.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.30.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.30.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.30.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.30.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.30.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.29.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.28.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.27.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.25.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.24.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.24.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.21.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.19.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.19.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.19.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.19.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.19.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.