← Home

@lukso/web-components

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

frozemanlukso-networkdzbojenea_vn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/chunks/index-DIfveR8p.js AI (source-diff): Tailwind/lit bundled CSS/JS build output. ai
source-diff obfuscated-file:dist/chunks/index-QpwaL8ie.js AI (source-diff): Tailwind/lit bundled CSS/JS build output. ai
source-diff obfuscated-file:dist/components/lukso-qr-code/index.cjs AI (source-diff): Bundled third-party qr-code-styling minified UMD, not custom obfuscation; matches new component. ai
phantom-deps phantom-dep:@lukso/core AI (phantom-deps): Same-org scoped dependency, expected. ai
publish-pattern new-deps-added AI (publish-pattern): Established libs (viem, tailwind, marked, etc.) match new UI components added this release. ai
source-diff large-new-source-files AI (source-diff): Bulk icon component files, consistent with package's stated icon library function. ai
source-diff obfuscated-file:dist/components/lukso-icon/vuesax/outline/setting-2.svg.cjs AI (source-diff): Long line is a minified SVG string asset, not true obfuscation. ai
source-diff obfuscated-file:dist/chunks/index-7BmB6zet.js AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. ai
source-diff obfuscated-file:dist/chunks/index-WbyPQW8n.js AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. ai
source-diff obfuscated-file:dist/chunks/index-xZkcKMCB.js AI (source-diff): bundled component chunk (lit/tailwind), build output. ai
source-diff obfuscated-file:dist/chunks/index-CWVksY60.js AI (source-diff): bundled component chunk (lit/tailwind), build output. ai
source-diff obfuscated-file:dist/chunks/index-DvaA_XMV.js AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. ai
source-diff net-exec-file:tools/axe-TH2R_oH7.js AI (source-diff): axe-core accessibility testing lib; no exfil/dropper behavior. ai
source-diff obfuscated-file:tools/axe-TH2R_oH7.js AI (source-diff): Bundled axe-core library, minified not obfuscated. ai
source-diff obfuscated-file:dist/chunks/index-DJzCzdSU.js AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. ai
source-diff net-exec-file:tools/axe-CMrnqurC.cjs AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. ai
source-diff obfuscated-file:tools/axe-Cc1s6soj.js AI (source-diff): Minified bundle of axe-core dep, not obfuscation. ai
source-diff net-exec-file:tools/axe-Cc1s6soj.js AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. ai
source-diff obfuscated-file:tools/axe-CMrnqurC.cjs AI (source-diff): Minified bundle of axe-core dep, not obfuscation. ai
source-diff net-exec-file:dist/axe-C-H1UVi1.cjs AI (source-diff): False positive: bundler boilerplate, not dropper/loader code. ai
phantom-deps phantom-dep:axe-core AI (phantom-deps): Bundled accessibility testing dep, referenced via config not direct import. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Used indirectly via component config; not a real risk for this UI toolkit. ai
source-diff obfuscated-file:dist/axe-C-H1UVi1.cjs AI (source-diff): CJS build of bundled axe-core, same as JS variant. ai
source-diff net-exec-file:dist/axe-BK9JSROP.js AI (source-diff): False positive: bundler import.meta.url resolution code, no real network+exec malware behavior. ai
source-diff obfuscated-file:dist/axe-BK9JSROP.js AI (source-diff): Bundled axe-core library output, not obfuscation; standard bundler boilerplate in sample. ai
source-diff obfuscated-file:dist/index-V6wvb6SH.js AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. ai
source-diff obfuscated-file:dist/index-D8IqXWcZ.cjs AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. ai
source-diff obfuscated-file:dist/index-C9vH8YlV.js AI (source-diff): Standard Vite/Rollup minified bundle output for a web-components library; LitElement license headers confirm legitimate build artifact. ai
source-diff obfuscated-file:dist/index-DkfODalz.cjs AI (source-diff): CJS counterpart of the same minified bundle; same reasoning as the ESM file. ai
source-diff net-exec-file:tools/axe-HmsG1pWb.cjs AI (source-diff): axe-core legitimately uses dynamic code execution for accessibility rule evaluation; not a dropper pattern. ai
source-diff obfuscated-file:tools/axe-HmsG1pWb.cjs AI (source-diff): File is a bundled copy of [email protected] (accessibility library); minification is expected, not malicious. ai
source-diff obfuscated-file:dist/index-ai1JMlH_.js AI (source-diff): Standard minified Lit/web-components build output with license headers; not obfuscation. ai
source-diff obfuscated-file:dist/index-sTnZd0lm.cjs AI (source-diff): CJS equivalent of the same minified Lit bundle; not obfuscation. ai
source-diff obfuscated-file:dist/index-KrWvJ44l.cjs AI (source-diff): Minified Lit/LitElement framework bundle (CJS variant); standard build output for this web-components package. ai
source-diff obfuscated-file:dist/index-BWp0TAbf.js AI (source-diff): Minified Lit/LitElement framework bundle; standard build output for this web-components package. ai
source-diff obfuscated-file:tools/axe-RWGhQLPE.js AI (source-diff): Bundled [email protected] ESM distribution; not obfuscated malware. ai
source-diff net-exec-file:tools/axe-Njf3Jvxk.cjs AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. ai
source-diff obfuscated-file:tools/axe-Njf3Jvxk.cjs AI (source-diff): Bundled [email protected] minified distribution; not obfuscated malware. ai
source-diff net-exec-file:tools/axe-RWGhQLPE.js AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. ai
source-diff obfuscated-file:dist/index-DKXUCmZ9.cjs AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. ai
source-diff obfuscated-file:dist/index-LyJ1o9RN.js AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. ai
source-diff obfuscated-file:dist/components/lukso-markdown/index.js AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. ai
source-diff obfuscated-file:dist/components/lukso-markdown/index.cjs AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. ai
source-diff obfuscated-file:dist/index-C1D2PVva.cjs AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-Ga3DorGn.js AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-DqZeY5Ft.js AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. ai
bogus-package bogus-package AI (bogus-package): Scoped org package bundles deps; missing metadata signals are false positives for this established library. ai
source-diff obfuscated-file:dist/index-CuduEaB2.cjs AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/index-DFCjzim8.js AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. ai
source-diff obfuscated-file:dist/index-ClAf3gfo.cjs AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. ai
source-diff net-exec-file:tools/axe-Dj3cSaX8.cjs AI (source-diff): axe-core uses network APIs for accessibility testing; not dropper behavior. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; legitimate automation migration. ai
source-diff obfuscated-file:tools/axe-Dj3cSaX8.cjs AI (source-diff): Bundled axe-core v4.11.1 accessibility library; minified by design, copyright header confirms identity. ai
phantom-deps phantom-dep:web3-utils AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:ethereum-blockies-base64 AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:tailwind-variants AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:tailwind-merge AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:tippy.js AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
dependencies unvetted-dep:@lukso/lsp-smart-contracts AI (dependencies): First-party LUKSO dependency; expected and stable for this package across versions. ai
npm-metadata no-description AI (npm-metadata): Long-lived official LUKSO package; missing description is a cosmetic issue, not a risk indicator. ai

Versions (showing 100 of 303)

Version Deps Published
1.71.3 5 / 0
1.71.2 5 / 0
1.71.1 5 / 0
1.71.0 5 / 0
1.70.1 5 / 0
1.70.0 5 / 0
1.69.0 5 / 0
1.68.1 5 / 0
1.68.0 5 / 0
1.67.0 5 / 0
1.66.1 5 / 0
1.66.0 5 / 0
1.65.0 5 / 0
1.64.1 5 / 0
1.64.0 5 / 0
1.63.0 5 / 0
1.62.0 5 / 0
1.61.0 5 / 0
1.60.2 5 / 0
1.60.1 5 / 0
1.60.0 5 / 0
1.59.0 5 / 0
1.58.0 5 / 0
1.57.1 5 / 0
1.57.0 5 / 0
1.56.1 5 / 0
1.56.0 5 / 0
1.55.0 5 / 0
1.54.0 5 / 0
1.53.2 5 / 0
1.53.1 5 / 0
1.53.0 5 / 0
1.52.2 5 / 0
1.52.1 5 / 0
1.52.0 5 / 0
1.51.6 2 / 0
1.51.5 2 / 0
1.51.4 2 / 0
1.51.3 2 / 0
1.51.2 2 / 0
1.51.1 2 / 0
1.51.0 2 / 0
1.50.0 2 / 0
1.49.2 1 / 0
1.49.1 1 / 0
1.49.0 1 / 0
1.48.0 1 / 0
1.47.1 1 / 0
1.47.0 1 / 0
1.46.0 1 / 0
1.45.0 1 / 0
1.44.0 1 / 0
1.43.0 1 / 0
1.42.0 1 / 0
1.41.0 1 / 0
1.40.0 1 / 0
1.39.0 1 / 0
1.38.0 1 / 0
1.37.0 1 / 0
1.36.0 1 / 0
1.35.0 1 / 0
1.34.1 1 / 0
1.34.0 1 / 0
1.33.1 1 / 0
1.33.0 1 / 0
1.32.1 1 / 0
1.32.0 1 / 0
1.31.1 1 / 0
1.31.0 1 / 0
1.30.0 1 / 0
1.29.0 1 / 0
1.28.0 1 / 0
1.27.0 1 / 0
1.26.2 1 / 0
1.26.1 1 / 0
1.26.0 1 / 0
1.25.0 1 / 0
1.24.0 1 / 0
1.23.0 1 / 0
1.22.2 1 / 0
1.21.0 1 / 0
1.20.1 1 / 0
1.20.0 1 / 0
1.19.1 1 / 0
1.19.0 1 / 0
1.18.0 1 / 0
1.17.1 1 / 0
1.17.0 1 / 0
1.16.0 1 / 0
1.15.0 1 / 0
1.14.1 1 / 0
1.14.0 1 / 0
1.13.1 1 / 0
1.13.0 1 / 0
1.12.0 1 / 0
1.11.0 1 / 0
1.10.0 1 / 0
1.9.0 1 / 0
1.8.1 1 / 0
1.8.0 1 / 0
Showing 100 of 303 Next page →

v1.71.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.70.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.70.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.69.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.68.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.68.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.67.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.66.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.66.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.65.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.64.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.64.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.63.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.62.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.61.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.60.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.60.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.60.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.59.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.58.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.57.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.57.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.56.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.56.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.55.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.54.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.53.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.53.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.53.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.52.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.52.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.52.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.49.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.49.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.49.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.47.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.47.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.44.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.39.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.36.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.35.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.34.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.34.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.33.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.33.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.32.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.32.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.31.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.31.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.30.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.29.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.26.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.26.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.22.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.