@jjlmoya/utils-hardware
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | postinstall.mjs copies the package's own src/tool/*.css into the consumer's public/styles/lib (node_modules-guarded; no network/exec). Benign CSS-asset step for this Astro utility scope. FP cleanup. | sean | |
| bogus-package | bogus-package | Benign self-referential postinstall (copies the package's own bundled tool CSS into the consumer public/styles/, node_modules-guarded, no net/exec). Legit @jjlmoya Astro calculator lib; spam-flag is metadata-only (no repo/description) FP. Sibling utils-* already accepted 2026-07-01. | sean |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 1.23.0 | 5 / 14 | |
| 1.17.0 | 5 / 14 | |
| 1.16.0 | 5 / 14 | |
| 1.15.0 | 5 / 14 | |
| 1.14.0 | 5 / 14 | |
| 1.13.0 | 5 / 14 | |
| 1.12.0 | 5 / 14 | |
| 1.11.0 | 5 / 14 | |
| 1.10.0 | 5 / 14 | |
| 1.9.0 | 5 / 14 | |
| 1.7.0 | 5 / 14 | |
| 1.6.0 | 5 / 14 | |
| 1.5.0 | 5 / 14 | |
| 1.3.0 | 4 / 14 | |
| 1.2.0 | 4 / 14 | |
| 1.1.0 | 4 / 14 |
v1.23.0
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): No repo, no description, no keywords — consistent with throwaway/malicious package pattern for this publisher.) Matched 4 signal(s), weighted score 6: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: jjlmoya. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.