@jjlmoya/utils-education
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | postinstall.mjs copies the package's own src/tool/*.css into the consumer's public/styles/lib (node_modules-guarded; no network/exec). Benign CSS-asset step for this Astro utility scope. FP cleanup. | sean |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 1.34.0 | 6 / 14 | |
| 1.33.0 | 6 / 14 | |
| 1.32.0 | 6 / 14 | |
| 1.31.0 | 6 / 14 | |
| 1.30.0 | 6 / 14 | |
| 1.29.0 | 6 / 14 | |
| 1.28.0 | 6 / 14 | |
| 1.27.0 | 6 / 14 | |
| 1.26.0 | 6 / 14 | |
| 1.25.0 | 6 / 14 | |
| 1.24.0 | 6 / 14 | |
| 1.19.0 | 5 / 14 | |
| 1.18.0 | 5 / 14 | |
| 1.17.0 | 5 / 14 | |
| 1.16.0 | 5 / 14 | |
| 1.15.0 | 5 / 14 | |
| 1.14.0 | 5 / 14 | |
| 1.13.0 | 5 / 14 | |
| 1.12.0 | 5 / 14 | |
| 1.11.0 | 5 / 14 | |
| 1.10.0 | 5 / 14 | |
| 1.9.0 | 4 / 14 | |
| 1.8.0 | 4 / 14 | |
| 1.7.0 | 4 / 14 | |
| 1.6.0 | 4 / 14 | |
| 1.5.0 | 4 / 14 | |
| 1.4.0 | 4 / 14 |
v1.34.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.29.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.28.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.27.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.26.0
3 findings[Always reject] Script: node scripts/postinstall.mjs
[Always reject] Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.