@lukso/web-components
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/chunks/index-DIfveR8p.js | AI (source-diff): Tailwind/lit bundled CSS/JS build output. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-QpwaL8ie.js | AI (source-diff): Tailwind/lit bundled CSS/JS build output. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-qr-code/index.cjs | AI (source-diff): Bundled third-party qr-code-styling minified UMD, not custom obfuscation; matches new component. | ai | |
| phantom-deps | phantom-dep:@lukso/core | AI (phantom-deps): Same-org scoped dependency, expected. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Established libs (viem, tailwind, marked, etc.) match new UI components added this release. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bulk icon component files, consistent with package's stated icon library function. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-icon/vuesax/outline/setting-2.svg.cjs | AI (source-diff): Long line is a minified SVG string asset, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-7BmB6zet.js | AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-WbyPQW8n.js | AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-xZkcKMCB.js | AI (source-diff): bundled component chunk (lit/tailwind), build output. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-CWVksY60.js | AI (source-diff): bundled component chunk (lit/tailwind), build output. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-DvaA_XMV.js | AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. | ai | |
| source-diff | net-exec-file:tools/axe-TH2R_oH7.js | AI (source-diff): axe-core accessibility testing lib; no exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:tools/axe-TH2R_oH7.js | AI (source-diff): Bundled axe-core library, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-DJzCzdSU.js | AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. | ai | |
| source-diff | net-exec-file:tools/axe-CMrnqurC.cjs | AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. | ai | |
| source-diff | obfuscated-file:tools/axe-Cc1s6soj.js | AI (source-diff): Minified bundle of axe-core dep, not obfuscation. | ai | |
| source-diff | net-exec-file:tools/axe-Cc1s6soj.js | AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. | ai | |
| source-diff | obfuscated-file:tools/axe-CMrnqurC.cjs | AI (source-diff): Minified bundle of axe-core dep, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/axe-C-H1UVi1.cjs | AI (source-diff): False positive: bundler boilerplate, not dropper/loader code. | ai | |
| phantom-deps | phantom-dep:axe-core | AI (phantom-deps): Bundled accessibility testing dep, referenced via config not direct import. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Used indirectly via component config; not a real risk for this UI toolkit. | ai | |
| source-diff | obfuscated-file:dist/axe-C-H1UVi1.cjs | AI (source-diff): CJS build of bundled axe-core, same as JS variant. | ai | |
| source-diff | net-exec-file:dist/axe-BK9JSROP.js | AI (source-diff): False positive: bundler import.meta.url resolution code, no real network+exec malware behavior. | ai | |
| source-diff | obfuscated-file:dist/axe-BK9JSROP.js | AI (source-diff): Bundled axe-core library output, not obfuscation; standard bundler boilerplate in sample. | ai | |
| source-diff | obfuscated-file:dist/index-V6wvb6SH.js | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. | ai | |
| source-diff | obfuscated-file:dist/index-D8IqXWcZ.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. | ai | |
| source-diff | obfuscated-file:dist/index-C9vH8YlV.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a web-components library; LitElement license headers confirm legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-DkfODalz.cjs | AI (source-diff): CJS counterpart of the same minified bundle; same reasoning as the ESM file. | ai | |
| source-diff | net-exec-file:tools/axe-HmsG1pWb.cjs | AI (source-diff): axe-core legitimately uses dynamic code execution for accessibility rule evaluation; not a dropper pattern. | ai | |
| source-diff | obfuscated-file:tools/axe-HmsG1pWb.cjs | AI (source-diff): File is a bundled copy of [email protected] (accessibility library); minification is expected, not malicious. | ai | |
| source-diff | obfuscated-file:dist/index-ai1JMlH_.js | AI (source-diff): Standard minified Lit/web-components build output with license headers; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-sTnZd0lm.cjs | AI (source-diff): CJS equivalent of the same minified Lit bundle; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-KrWvJ44l.cjs | AI (source-diff): Minified Lit/LitElement framework bundle (CJS variant); standard build output for this web-components package. | ai | |
| source-diff | obfuscated-file:dist/index-BWp0TAbf.js | AI (source-diff): Minified Lit/LitElement framework bundle; standard build output for this web-components package. | ai | |
| source-diff | obfuscated-file:tools/axe-RWGhQLPE.js | AI (source-diff): Bundled [email protected] ESM distribution; not obfuscated malware. | ai | |
| source-diff | net-exec-file:tools/axe-Njf3Jvxk.cjs | AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. | ai | |
| source-diff | obfuscated-file:tools/axe-Njf3Jvxk.cjs | AI (source-diff): Bundled [email protected] minified distribution; not obfuscated malware. | ai | |
| source-diff | net-exec-file:tools/axe-RWGhQLPE.js | AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. | ai | |
| source-diff | obfuscated-file:dist/index-DKXUCmZ9.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-LyJ1o9RN.js | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-markdown/index.js | AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-markdown/index.cjs | AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. | ai | |
| source-diff | obfuscated-file:dist/index-C1D2PVva.cjs | AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-Ga3DorGn.js | AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-DqZeY5Ft.js | AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org package bundles deps; missing metadata signals are false positives for this established library. | ai | |
| source-diff | obfuscated-file:dist/index-CuduEaB2.cjs | AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/index-DFCjzim8.js | AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-ClAf3gfo.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. | ai | |
| source-diff | net-exec-file:tools/axe-Dj3cSaX8.cjs | AI (source-diff): axe-core uses network APIs for accessibility testing; not dropper behavior. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; legitimate automation migration. | ai | |
| source-diff | obfuscated-file:tools/axe-Dj3cSaX8.cjs | AI (source-diff): Bundled axe-core v4.11.1 accessibility library; minified by design, copyright header confirms identity. | ai | |
| phantom-deps | phantom-dep:web3-utils | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:ethereum-blockies-base64 | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:tailwind-variants | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:tippy.js | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| dependencies | unvetted-dep:@lukso/lsp-smart-contracts | AI (dependencies): First-party LUKSO dependency; expected and stable for this package across versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Long-lived official LUKSO package; missing description is a cosmetic issue, not a risk indicator. | ai |
Versions (showing 100 of 303)
| Version | Deps | Published |
|---|---|---|
| 1.141.1 | 0 / 0 | |
| 1.141.0 | 0 / 0 | |
| 1.140.0 | 0 / 0 | |
| 1.139.0 | 6 / 0 | |
| 1.138.0 | 6 / 0 | |
| 1.137.0 | 6 / 0 | |
| 1.136.0 | 6 / 0 | |
| 1.135.0 | 6 / 0 | |
| 1.134.2 | 6 / 0 | |
| 1.134.1 | 6 / 0 | |
| 1.134.0 | 6 / 0 | |
| 1.133.0 | 6 / 0 | |
| 1.132.1 | 6 / 0 | |
| 1.132.0 | 6 / 0 | |
| 1.131.1 | 6 / 0 | |
| 1.131.0 | 6 / 0 | |
| 1.130.0 | 6 / 0 | |
| 1.129.0 | 6 / 0 | |
| 1.128.0 | 6 / 0 | |
| 1.127.0 | 6 / 0 | |
| 1.126.0 | 6 / 0 | |
| 1.125.0 | 6 / 0 | |
| 1.124.0 | 6 / 0 | |
| 1.123.0 | 6 / 0 | |
| 1.122.0 | 6 / 0 | |
| 1.121.0 | 6 / 0 | |
| 1.120.0 | 6 / 0 | |
| 1.119.1 | 6 / 0 | |
| 1.119.0 | 6 / 0 | |
| 1.118.0 | 6 / 0 | |
| 1.117.0 | 6 / 0 | |
| 1.116.2 | 6 / 0 | |
| 1.116.1 | 6 / 0 | |
| 1.116.0 | 6 / 0 | |
| 1.115.3 | 6 / 0 | |
| 1.115.2 | 6 / 0 | |
| 1.114.0 | 6 / 0 | |
| 1.113.0 | 6 / 0 | |
| 1.112.1 | 6 / 0 | |
| 1.112.0 | 6 / 0 | |
| 1.111.0 | 6 / 0 | |
| 1.110.0 | 6 / 0 | |
| 1.109.1 | 6 / 0 | |
| 1.109.0 | 6 / 0 | |
| 1.108.1 | 6 / 0 | |
| 1.108.0 | 6 / 0 | |
| 1.107.1 | 6 / 0 | |
| 1.107.0 | 6 / 0 | |
| 1.106.1 | 6 / 0 | |
| 1.106.0 | 6 / 0 | |
| 1.105.0 | 6 / 0 | |
| 1.104.0 | 6 / 0 | |
| 1.103.0 | 6 / 0 | |
| 1.102.2 | 6 / 0 | |
| 1.102.1 | 6 / 0 | |
| 1.102.0 | 6 / 0 | |
| 1.101.2 | 6 / 0 | |
| 1.101.1 | 6 / 0 | |
| 1.101.0 | 6 / 0 | |
| 1.100.0 | 6 / 0 | |
| 1.99.1 | 6 / 0 | |
| 1.99.0 | 6 / 0 | |
| 1.98.0 | 6 / 0 | |
| 1.97.0 | 6 / 0 | |
| 1.96.0 | 6 / 0 | |
| 1.95.0 | 6 / 0 | |
| 1.94.2 | 6 / 0 | |
| 1.94.1 | 6 / 0 | |
| 1.94.0 | 6 / 0 | |
| 1.93.0 | 6 / 0 | |
| 1.92.0 | 6 / 0 | |
| 1.91.0 | 6 / 0 | |
| 1.90.0 | 6 / 0 | |
| 1.89.0 | 6 / 0 | |
| 1.88.1 | 6 / 0 | |
| 1.88.0 | 6 / 0 | |
| 1.87.0 | 6 / 0 | |
| 1.86.0 | 6 / 0 | |
| 1.85.1 | 6 / 0 | |
| 1.85.0 | 6 / 0 | |
| 1.84.0 | 6 / 0 | |
| 1.83.0 | 6 / 0 | |
| 1.82.0 | 6 / 0 | |
| 1.81.3 | 5 / 0 | |
| 1.81.2 | 5 / 0 | |
| 1.81.1 | 5 / 0 | |
| 1.81.0 | 5 / 0 | |
| 1.80.0 | 5 / 0 | |
| 1.79.0 | 5 / 0 | |
| 1.78.0 | 5 / 0 | |
| 1.77.0 | 5 / 0 | |
| 1.76.0 | 5 / 0 | |
| 1.75.0 | 5 / 0 | |
| 1.74.3 | 5 / 0 | |
| 1.74.2 | 5 / 0 | |
| 1.74.1 | 6 / 0 | |
| 1.74.0 | 6 / 0 | |
| 1.73.0 | 6 / 0 | |
| 1.72.0 | 5 / 0 | |
| 1.71.4 | 5 / 0 |
v1.122.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.121.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.119.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.119.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.118.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.117.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.116.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.116.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.116.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.115.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.115.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.114.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.113.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.112.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.112.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.111.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.110.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.109.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.109.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.108.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.108.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.107.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.107.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.106.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.106.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.105.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.104.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.103.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.102.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.102.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.102.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.101.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.101.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.101.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.100.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.99.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.99.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.98.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.97.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.96.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.95.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.94.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.94.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.94.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.93.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.92.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.91.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.90.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.89.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.88.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.88.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.87.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.86.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.85.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.85.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.84.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.83.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.82.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.81.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.81.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.81.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.81.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.80.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.79.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.