@ludeo/cloud-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher is consistent with org-level automation; 846-version history and no code changes support legitimacy. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer rshaham-ludeo is within the @ludeo org namespace; consistent with internal team change. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Bulk removal of @ludeo-affiliated maintainers matches an org-internal rotation, not a hostile takeover. | ai | |
| dependencies | unvetted-dep:@ludeo/aws-gamecast-sdk | AI (dependencies): Same-org scoped dependency; consistent with internal SDK ecosystem across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Private org package; no provenance is consistent across all 816+ versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal org package; no public description is consistent across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped package with 816 versions; missing public metadata is expected for private org tooling. | ai | |
| phantom-deps | phantom-dep:jest | AI (phantom-deps): jest is declared as a runtime dep (likely a packaging oversight); not a security concern for this internal package. | ai |
Versions (showing 86 of 86)
| Version | Deps | Published |
|---|---|---|
| 1.2.268 | 6 / 4 | |
| 1.2.267 | 6 / 4 | |
| 1.2.266 | 6 / 4 | |
| 1.2.264 | 6 / 4 | |
| 1.2.263 | 6 / 4 | |
| 1.2.262 | 6 / 4 | |
| 1.2.261 | 6 / 4 | |
| 1.2.260 | 6 / 4 | |
| 1.2.258 | 6 / 4 | |
| 1.2.256 | 6 / 4 | |
| 1.2.253 | 6 / 4 | |
| 1.2.252 | 6 / 4 | |
| 1.2.251 | 6 / 4 | |
| 1.2.250 | 6 / 4 | |
| 1.2.249 | 6 / 4 | |
| 1.2.248 | 6 / 4 | |
| 1.2.245 | 6 / 4 | |
| 1.2.244 | 6 / 4 | |
| 1.2.243 | 6 / 4 | |
| 1.2.242 | 6 / 4 | |
| 1.2.241 | 6 / 4 | |
| 1.2.240 | 6 / 4 | |
| 1.2.239 | 6 / 4 | |
| 1.2.237 | 6 / 4 | |
| 1.2.236 | 6 / 4 | |
| 1.2.234 | 6 / 4 | |
| 1.2.231 | 6 / 4 | |
| 1.2.230 | 6 / 4 | |
| 1.2.229 | 6 / 4 | |
| 1.2.228 | 6 / 4 | |
| 1.2.227 | 6 / 4 | |
| 1.2.226 | 6 / 4 | |
| 1.2.224 | 6 / 4 | |
| 1.2.223 | 6 / 4 | |
| 1.2.219 | 6 / 4 | |
| 1.2.217 | 6 / 4 | |
| 1.2.215 | 6 / 4 | |
| 1.2.214 | 6 / 4 | |
| 1.2.212 | 6 / 4 | |
| 1.2.211 | 6 / 4 | |
| 1.2.209 | 6 / 4 | |
| 1.2.207 | 6 / 4 | |
| 1.2.206 | 6 / 4 | |
| 1.2.204 | 6 / 4 | |
| 1.2.202 | 6 / 4 | |
| 1.2.201 | 6 / 4 | |
| 1.2.200 | 6 / 4 | |
| 1.2.198 | 6 / 4 | |
| 1.2.196 | 6 / 4 | |
| 1.2.195 | 6 / 4 | |
| 1.2.191 | 6 / 4 | |
| 1.2.190 | 6 / 4 | |
| 1.2.189 | 6 / 4 | |
| 1.2.186 | 6 / 4 | |
| 1.2.183 | 6 / 4 | |
| 1.2.182 | 6 / 4 | |
| 1.2.181 | 6 / 4 | |
| 1.2.180 | 6 / 4 | |
| 1.2.179 | 6 / 4 | |
| 1.2.178 | 6 / 4 | |
| 1.2.177 | 6 / 4 | |
| 1.2.176 | 6 / 4 | |
| 1.2.172 | 6 / 4 | |
| 1.2.169 | 6 / 4 | |
| 1.2.166 | 6 / 4 | |
| 1.2.164 | 6 / 4 | |
| 1.2.163 | 6 / 4 | |
| 1.2.161 | 5 / 4 | |
| 1.2.160 | 5 / 4 | |
| 1.2.159 | 5 / 4 | |
| 1.2.158 | 5 / 4 | |
| 1.2.157 | 5 / 4 | |
| 1.2.156 | 5 / 4 | |
| 1.2.155 | 5 / 4 | |
| 1.2.152 | 5 / 4 | |
| 1.2.151 | 5 / 4 | |
| 1.2.146 | 5 / 4 | |
| 1.2.144 | 5 / 4 | |
| 1.2.142 | 5 / 4 | |
| 1.2.140 | 5 / 4 | |
| 1.2.139 | 5 / 4 | |
| 1.2.138 | 5 / 4 | |
| 1.2.137 | 5 / 4 | |
| 1.2.134 | 5 / 4 | |
| 1.2.133 | 5 / 4 | |
| 1.2.132 | 5 / 4 |
v1.2.268
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.267
2 findingsThis version was published by a different npm account than previous versions on 2026-06-02. This could indicate a legitimate maintainer transition or an account compromise.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.266
2 findingsThis version was published by a different npm account than previous versions on 2026-06-02. This could indicate a legitimate maintainer transition or an account compromise.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.264
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.263
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.262
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.261
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.260
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.258
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.256
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.253
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.251
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.250
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.249
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.248
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.245
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.244
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.243
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.242
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.241
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.240
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.239
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.237
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.236
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.234
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.231
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.230
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.229
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.228
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.227
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.226
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.224
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.223
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.219
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.217
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.215
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.214
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.212
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.211
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.209
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.207
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.206
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.204
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.202
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.201
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.200
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.198
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.196
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.195
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.190
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.189
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.183
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.182
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.181
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.180
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.179
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.178
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.177
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.176
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.172
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.169
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.166
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.164
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.163
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.161
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.160
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.159
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.158
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.157
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.156
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.152
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.146
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.144
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.142
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.140
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.139
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.138
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.137
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.134
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.133
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.132
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.