← Home

@makerx/node-winston

A set of winston formats, console transport and logger creation functions

7
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

patrick.dinhmakerx-engineeringmakerxuserplebsorivatsalyagoel

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): v2.0.0 major refactor adds dual CJS/ESM build outputs; size increase is structural, not injected payload. ai
source-diff source-size-tripled AI (source-diff): Size increase from dual-module build artifacts and new source structure, not bundled malicious code. ai
bogus-package bogus-package AI (bogus-package): Legitimate MakerX org package; README and metadata style are consistent across versions, not spam. ai
phantom-deps phantom-dep:triple-beam AI (phantom-deps): triple-beam is a peer/transitive dep of winston; declaring it explicitly is a valid pinning pattern. ai
typosquat typosquat.pattern:winston AI (typosquat): Scoped @makerx package intentionally wrapping winston; not a typosquat. ai

Versions (showing 7 of 7)

Version Deps Published
2.0.1 3 / 0
2.0.0 3 / 0
1.3.1 10 / 0
1.3.0 3 / 0
1.2.0 10 / 0
1.1.0 10 / 0
1.0.0 10 / 0

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.