← Home

@makerx/node-winston

A set of winston formats, console transport and logger creation functions

4
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

patrick.dinhmakerx-engineeringmakerxuserplebsorivatsalyagoel

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): v2.0.0 major refactor adds dual CJS/ESM build outputs; size increase is structural, not injected payload. ai
source-diff source-size-tripled AI (source-diff): Size increase from dual-module build artifacts and new source structure, not bundled malicious code. ai
bogus-package bogus-package AI (bogus-package): Legitimate MakerX org package; README and metadata style are consistent across versions, not spam. ai
phantom-deps phantom-dep:triple-beam AI (phantom-deps): triple-beam is a peer/transitive dep of winston; declaring it explicitly is a valid pinning pattern. ai
typosquat typosquat.pattern:winston AI (typosquat): Scoped @makerx package intentionally wrapping winston; not a typosquat. ai

Versions (showing 4 of 4)

Version Deps Published
2.0.1 3 / 0
2.0.0 3 / 0
1.3.1 10 / 0
1.3.0 3 / 0

v2.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

2 findings
HIGH typosquat.pattern: Suspicious name similarity to 'winston' typosquat

Package name '@makerx/node-winston' matches a known typosquatting pattern (hyphen swap, prefix/suffix) of 'winston'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.