@lexical/react
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Monorepo build output growth; expected for this package. | ai | |
| source-diff | obfuscated-file:LexicalCheckListPlugin.prod.mjs | AI (source-diff): Minified prod build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalCharacterLimitPlugin.prod.mjs | AI (source-diff): Minified prod build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalHashtagPlugin.dev.mjs | AI (source-diff): Dev build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalCollaborationPlugin.prod.mjs | AI (source-diff): Minified prod build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalAutoLinkPlugin.prod.mjs | AI (source-diff): Minified prod build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalNodeMenuPlugin.prod.mjs | AI (source-diff): Minified prod build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalContextMenuPlugin.prod.mjs | AI (source-diff): Minified prod build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalTypeaheadMenuPlugin.prod.mjs | AI (source-diff): Minified prod build output; benign for this package. | ai | |
| source-diff | obfuscated-file:LexicalTreeView.prod.mjs | AI (source-diff): Minified prod build output with Meta header/readable imports; not obfuscation. | ai | |
| provenance | publisher-changed-stale | AI (provenance): 2022 publisher change unremoved 1565d; inconsistent with takeover. | ai | |
| source-diff | obfuscated-file:LexicalHashtagPlugin.prod.js | AI (source-diff): Minified Rollup build output with Meta license header; not obfuscation. | ai | |
| source-diff | obfuscated-file:LexicalHashtagPlugin.dev.js | AI (source-diff): Long lines are Unicode regex tables in build output, not obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Legit org handoff to acywatson, stable on npm for years. | ai | |
| dependencies | unvetted-dep:@lexical/helpers | AI (dependencies): Same-org sibling package in the Lexical monorepo, not an unvetted third party. | ai | |
| phantom-deps | phantom-dep:@lexical/helpers | AI (phantom-deps): Same-org monorepo dependency; heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react-error-boundary | AI (phantom-deps): Config-referenced error boundary; stable for this package. | ai | |
| phantom-deps | phantom-dep:@lexical/code | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@lexical/clipboard | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@lexical/selection | AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@lexical/a11y | AI (dependencies): Same-org sibling package, same version, part of lexical monorepo lockstep release. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is first-party @lexical/* sibling, not an external/unrelated package. | ai | |
| provenance | missing-githead | AI (provenance): gitHead dropped as part of CI/CD migration; SLSA attestation provides stronger provenance. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from manual publish (zurfyx) to GitHub Actions CI/CD is expected for facebook/lexical. | ai | |
| source-diff | obfuscated-file:dist/LexicalDraggableBlockPlugin.prod.js | AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:dist/LexicalCollaborationPlugin.prod.js | AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:dist/LexicalCharacterLimitPlugin.prod.js | AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Monorepo build restructuring; all files are expected dist outputs. | ai | |
| dependencies | unvetted-dep:@lexical/plain-text | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/rich-text | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/extension | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/overflow | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/markdown | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/history | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/hashtag | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/dragon | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/utils | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/table | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/text | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/mark | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/list | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| dependencies | unvetted-dep:@lexical/yjs | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. Not a third-party dependency. | ai | |
| dependencies | unvetted-dep:@lexical/link | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai | |
| provenance | no-provenance | AI (provenance): Lexical does not publish with Sigstore provenance; this is consistent across all versions and is not a security disqualifier for this established package. | ai | |
| phantom-deps | phantom-dep:@lexical/mark | AI (phantom-deps): Same-org sibling dependency; phantom import is a packaging detail, not a security concern for this monorepo package. | ai | |
| dependencies | unvetted-dep:@lexical/devtools-core | AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. | ai |
Versions (showing 100 of 136)
| Version | Deps | Published |
|---|---|---|
| 0.48.0 | 20 / 2 | |
| 0.47.0 | 20 / 2 | |
| 0.46.0 | 19 / 2 | |
| 0.45.0 | 20 / 2 | |
| 0.44.0 | 19 / 2 | |
| 0.43.0 | 19 / 2 | |
| 0.42.0 | 19 / 2 | |
| 0.41.0 | 19 / 2 | |
| 0.40.0 | 19 / 2 | |
| 0.39.0 | 19 / 2 | |
| 0.38.2 | 19 / 2 | |
| 0.38.1 | 19 / 2 | |
| 0.38.0 | 19 / 2 | |
| 0.37.0 | 19 / 2 | |
| 0.36.2 | 19 / 2 | |
| 0.36.1 | 19 / 2 | |
| 0.36.0 | 19 / 2 | |
| 0.35.0 | 18 / 2 | |
| 0.34.0 | 18 / 2 | |
| 0.33.1 | 18 / 2 | |
| 0.33.0 | 18 / 2 | |
| 0.32.1 | 18 / 0 | |
| 0.32.0 | 18 / 0 | |
| 0.31.2 | 17 / 0 | |
| 0.31.1 | 17 / 0 | |
| 0.31.0 | 17 / 0 | |
| 0.30.0 | 17 / 0 | |
| 0.29.0 | 17 / 0 | |
| 0.28.0 | 17 / 0 | |
| 0.27.2 | 20 / 0 | |
| 0.27.1 | 20 / 0 | |
| 0.27.0 | 20 / 0 | |
| 0.26.0 | 20 / 0 | |
| 0.25.0 | 20 / 0 | |
| 0.24.0 | 20 / 0 | |
| 0.23.1 | 20 / 0 | |
| 0.23.0 | 20 / 0 | |
| 0.22.0 | 20 / 0 | |
| 0.21.0 | 20 / 0 | |
| 0.20.2 | 20 / 0 | |
| 0.20.1 | 20 / 0 | |
| 0.20.0 | 20 / 0 | |
| 0.19.0 | 20 / 0 | |
| 0.18.0 | 20 / 0 | |
| 0.17.1 | 20 / 0 | |
| 0.17.0 | 20 / 0 | |
| 0.16.1 | 20 / 0 | |
| 0.16.0 | 20 / 0 | |
| 0.15.0 | 20 / 0 | |
| 0.14.5 | 20 / 0 | |
| 0.14.4 | 19 / 0 | |
| 0.14.3 | 19 / 0 | |
| 0.14.2 | 18 / 0 | |
| 0.14.1 | 18 / 0 | |
| 0.14.0 | 18 / 0 | |
| 0.13.1 | 18 / 0 | |
| 0.13.0 | 18 / 0 | |
| 0.12.6 | 18 / 0 | |
| 0.12.5 | 18 / 0 | |
| 0.12.4 | 18 / 0 | |
| 0.12.3 | 18 / 0 | |
| 0.12.2 | 18 / 0 | |
| 0.12.1 | 18 / 0 | |
| 0.12.0 | 18 / 0 | |
| 0.11.3 | 18 / 0 | |
| 0.11.2 | 18 / 0 | |
| 0.11.1 | 18 / 0 | |
| 0.11.0 | 18 / 0 | |
| 0.10.0 | 18 / 0 | |
| 0.9.2 | 18 / 0 | |
| 0.9.1 | 18 / 0 | |
| 0.9.0 | 18 / 0 | |
| 0.8.1 | 18 / 0 | |
| 0.8.0 | 18 / 0 | |
| 0.7.9 | 18 / 0 | |
| 0.7.8 | 18 / 0 | |
| 0.7.7 | 18 / 0 | |
| 0.7.6 | 18 / 0 | |
| 0.7.5 | 18 / 0 | |
| 0.7.4 | 18 / 0 | |
| 0.7.3 | 18 / 0 | |
| 0.7.2 | 18 / 0 | |
| 0.7.1 | 18 / 0 | |
| 0.7.0 | 18 / 0 | |
| 0.6.5 | 18 / 0 | |
| 0.6.4 | 18 / 0 | |
| 0.6.3 | 18 / 0 | |
| 0.6.2 | 18 / 0 | |
| 0.6.0 | 18 / 0 | |
| 0.5.0 | 17 / 0 | |
| 0.4.1 | 17 / 0 | |
| 0.4.0 | 17 / 0 | |
| 0.3.11 | 17 / 0 | |
| 0.3.10 | 17 / 0 | |
| 0.3.9 | 17 / 0 | |
| 0.3.8 | 17 / 0 | |
| 0.3.7 | 17 / 0 | |
| 0.3.6 | 17 / 0 | |
| 0.3.5 | 17 / 1 | |
| 0.3.4 | 17 / 1 |
v0.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.42.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zurfyx.
v0.41.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zurfyx.
v0.40.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zurfyx.
v0.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.27.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.27.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.14.5
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2024-04-17. It has since remained available on npm for 825 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.4
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2024-04-16. It has since remained available on npm for 825 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2024-04-03. It has since remained available on npm for 838 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2024-03-18. It has since remained available on npm for 854 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (ipavlov001) than the most recent previously approved version (trueadm) on 2024-03-18. It has since remained available on npm for 855 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (ipavlov001) than the most recent previously approved version (trueadm) on 2024-03-18. It has since remained available on npm for 855 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2024-01-26, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.13.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2024-01-24, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.12.6
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2024-01-08. It has since remained available on npm for 924 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2023-12-06. It has since remained available on npm for 957 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.4
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-11-17, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.12.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2023-11-17. It has since remained available on npm for 976 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-09-08, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.12.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-09-08, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.12.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2023-08-10. It has since remained available on npm for 1075 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-07-19, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-07-11, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-05-26, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-05-24, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2023-04-18. It has since remained available on npm for 1189 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2023-04-14. It has since remained available on npm for 1193 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2023-03-24, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2023-03-09. It has since remained available on npm for 1229 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2023-02-23. It has since remained available on npm for 1243 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2023-02-09. It has since remained available on npm for 1257 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.9
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2023-02-09. It has since remained available on npm for 1257 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.4
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2022-12-20. It has since remained available on npm for 1308 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2022-12-11. It has since remained available on npm for 1317 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-10-31, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.5.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-09-23, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2022-09-05. It has since remained available on npm for 1414 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-09-04. It has since remained available on npm for 1416 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.11
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (fantactuka) than the most recent previously approved version (trueadm) on 2022-08-12. It has since remained available on npm for 1438 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.10
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-08-12, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.9
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-08-11, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.8
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2022-07-21. It has since remained available on npm for 1460 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.7
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-07-07, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.6
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-06-29, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-06-16, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.3.4
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (tylerbainbridge) than the most recent previously approved version (trueadm) on 2022-06-16. It has since remained available on npm for 1495 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.