@live-change/blog-service
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Consistently empty description across 389 versions; monorepo package pattern, not a malware indicator. | ai | |
| phantom-deps | phantom-dep:lru-cache | AI (phantom-deps): Likely used transitively or in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pluralize | AI (phantom-deps): Likely used transitively or in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:progress-stream | AI (phantom-deps): Likely used transitively or in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:prosemirror-model | AI (phantom-deps): Likely used transitively or in config; stable false positive for this package. | ai |
Versions (showing 45 of 45)
| Version | Deps | Published |
|---|---|---|
| 0.9.209 | 6 / 0 | |
| 0.9.208 | 6 / 0 | |
| 0.9.207 | 6 / 0 | |
| 0.9.206 | 6 / 0 | |
| 0.9.205 | 6 / 0 | |
| 0.9.204 | 6 / 0 | |
| 0.9.199 | 6 / 0 | |
| 0.9.196 | 6 / 0 | |
| 0.9.190 | 6 / 0 | |
| 0.9.188 | 6 / 0 | |
| 0.9.184 | 6 / 0 | |
| 0.9.183 | 6 / 0 | |
| 0.9.177 | 6 / 0 | |
| 0.9.175 | 6 / 0 | |
| 0.9.173 | 6 / 0 | |
| 0.9.165 | 6 / 0 | |
| 0.9.164 | 6 / 0 | |
| 0.9.158 | 6 / 0 | |
| 0.9.157 | 6 / 0 | |
| 0.9.153 | 6 / 0 | |
| 0.9.146 | 6 / 0 | |
| 0.9.143 | 6 / 0 | |
| 0.9.142 | 6 / 0 | |
| 0.9.141 | 6 / 0 | |
| 0.9.136 | 6 / 0 | |
| 0.9.133 | 6 / 0 | |
| 0.9.127 | 6 / 0 | |
| 0.9.125 | 6 / 0 | |
| 0.9.120 | 6 / 0 | |
| 0.9.116 | 6 / 0 | |
| 0.9.112 | 6 / 0 | |
| 0.9.107 | 6 / 0 | |
| 0.9.106 | 6 / 0 | |
| 0.9.104 | 6 / 0 | |
| 0.9.101 | 6 / 0 | |
| 0.9.98 | 6 / 0 | |
| 0.9.94 | 6 / 0 | |
| 0.9.93 | 6 / 0 | |
| 0.9.92 | 6 / 0 | |
| 0.9.87 | 6 / 0 | |
| 0.9.82 | 6 / 0 | |
| 0.9.79 | 6 / 0 | |
| 0.9.76 | 6 / 0 | |
| 0.9.72 | 6 / 0 | |
| 0.9.71 | 6 / 0 |
v0.9.209
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.208
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.207
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.206
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.205
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.199
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.196
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.190
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.188
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.184
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.183
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.177
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.175
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.173
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.164
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.158
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.157
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.153
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.146
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.143
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.142
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.141
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.136
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.133
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.127
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.125
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.120
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.116
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.112
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.107
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.106
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.104
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.101
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.98
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.94
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.93
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.92
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.87
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.82
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.79
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.76
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.72
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.71
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.