← Home

@nocobase/devtools

<video width="100%" controls> <source src="https://github.com/user-attachments/assets/4d11a87b-00e2-48f3-9bf7-389d21072d13" type="video/mp4"> </video>

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

chenosjiannlu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): TS ESLint parser referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:eslint-plugin-prettier AI (phantom-deps): ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:eslint-plugin-markdown AI (phantom-deps): ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): ESLint config referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:eslint-plugin-promise AI (phantom-deps): ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:eslint-plugin-react AI (phantom-deps): ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:@types/koa-bodyparser AI (phantom-deps): Type-only dep loaded by convention; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-plugin-import AI (phantom-deps): ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): TS ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
dependencies unvetted-dep:@types/koa-bodyparser AI (dependencies): Type-only dev dependency; no runtime risk for this devtools package. ai
phantom-deps phantom-dep:eslint-plugin-node AI (phantom-deps): ESLint plugin referenced in config; expected pattern for devtools aggregator. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Type-only package; convention-loaded, stable false positive. ai
phantom-deps phantom-dep:concurrently AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): Type-only package; convention-loaded, stable false positive. ai
phantom-deps phantom-dep:pretty-format AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:@nocobase/test AI (phantom-deps): Same-org package; stable false positive for this devtools aggregator. ai
phantom-deps phantom-dep:@nocobase/build AI (phantom-deps): Same-org package; stable false positive for this devtools aggregator. ai
phantom-deps phantom-dep:@nocobase/client AI (phantom-deps): Same-org package; stable false positive for this devtools aggregator. ai
phantom-deps phantom-dep:@types/react-dom AI (phantom-deps): Type-only package; convention-loaded, stable false positive. ai
phantom-deps phantom-dep:tsconfig-paths AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:pretty-quick AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:serve AI (phantom-deps): Devtools aggregator; deps referenced in config files, not direct imports — stable pattern for this package. ai
phantom-deps phantom-dep:rimraf AI (phantom-deps): Devtools aggregator; config-file reference pattern, not a real phantom dep. ai
phantom-deps phantom-dep:ts-node AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:tinybench AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:ts-loader AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:@types/koa AI (phantom-deps): Type-only package; convention-loaded, stable false positive. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Type-only package; convention-loaded, stable false positive. ai
phantom-deps phantom-dep:ts-node-dev AI (phantom-deps): Devtools aggregator; config-file reference pattern. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): Devtools aggregator package; all phantom deps are CLI/config tools declared for monorepo consumers, not directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:react AI (phantom-deps): Devtools aggregator; react declared for monorepo consumers, not directly imported. Expected pattern. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): Devtools aggregator; prettier consumed via CLI/config. Expected pattern. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Devtools aggregator; typescript consumed via CLI/config. Expected pattern. ai
phantom-deps phantom-dep:eslint AI (phantom-deps): Devtools aggregator; eslint consumed via config/CLI, not direct import. Expected pattern. ai
phantom-deps phantom-dep:lerna AI (phantom-deps): Devtools aggregator; lerna is a CLI tool declared as dep for monorepo consumers. Expected pattern. ai
phantom-deps phantom-dep:umi AI (phantom-deps): Devtools aggregator package; umi is a declared dep consumed via CLI/config, not direct JS import. Expected pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require loads plugin package.json files discovered via glob path — standard plugin discovery pattern, not arbitrary code execution. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): The raw IP is 127.0.0.1 (localhost) used as a dev proxy target in umiConfig.js — completely benign for a devtools package. ai
bogus-package bogus-package AI (bogus-package): Devtools aggregator whose value is transitive deps; empty main and link-heavy README are consistent with this pattern for @nocobase/devtools. ai

Versions (showing 100 of 125)

Version Deps Published
2.0.61 39 / 0
2.0.60 39 / 0
2.0.59 39 / 0
2.0.58 39 / 0
2.0.57 39 / 0
2.0.56 39 / 0
2.0.55 39 / 0
2.0.54 39 / 0
2.0.53 39 / 0
2.0.52 39 / 0
2.0.51 39 / 0
2.0.50 39 / 0
2.0.49 39 / 0
2.0.48 39 / 0
2.0.47 39 / 0
2.0.46 39 / 0
2.0.45 39 / 0
2.0.44 39 / 0
2.0.43 39 / 0
2.0.42 39 / 0
2.0.41 39 / 0
2.0.40 39 / 0
2.0.39 39 / 0
2.0.38 39 / 0
2.0.37 39 / 0
2.0.36 39 / 0
2.0.35 39 / 0
2.0.34 39 / 0
2.0.33 39 / 0
2.0.32 39 / 0
2.0.31 39 / 0
2.0.30 39 / 0
2.0.29 39 / 0
2.0.28 39 / 0
2.0.27 39 / 0
2.0.26 39 / 0
2.0.25 39 / 0
2.0.24 39 / 0
2.0.23 39 / 0
2.0.22 39 / 0
2.0.21 39 / 0
2.0.20 39 / 0
2.0.19 39 / 0
2.0.18 39 / 0
2.0.17 39 / 0
2.0.16 39 / 0
2.0.15 39 / 0
2.0.14 39 / 0
2.0.13 39 / 0
2.0.12 39 / 0
2.0.11 39 / 0
2.0.10 39 / 0
2.0.9 39 / 0
2.0.8 39 / 0
2.0.7 39 / 0
2.0.6 39 / 0
2.0.5 39 / 0
2.0.3 39 / 0
2.0.2 39 / 0
2.0.1 39 / 0
2.0.0 39 / 0
1.9.63 39 / 0
1.9.62 39 / 0
1.9.61 39 / 0
1.9.60 39 / 0
1.9.59 39 / 0
1.9.58 39 / 0
1.9.57 39 / 0
1.9.56 39 / 0
1.9.55 39 / 0
1.9.54 39 / 0
1.9.53 39 / 0
1.9.52 39 / 0
1.9.51 39 / 0
1.9.49 39 / 0
1.9.47 39 / 0
1.9.46 39 / 0
1.9.45 39 / 0
1.9.44 39 / 0
1.9.43 39 / 0
1.9.42 39 / 0
1.9.41 39 / 0
1.9.40 39 / 0
1.9.39 39 / 0
1.9.38 39 / 0
1.9.37 39 / 0
1.9.36 39 / 0
1.9.35 39 / 0
1.9.34 39 / 0
1.9.33 39 / 0
1.9.32 39 / 0
1.9.31 39 / 0
1.9.30 39 / 0
1.9.29 39 / 0
1.9.28 39 / 0
1.9.27 39 / 0
1.9.26 39 / 0
1.9.25 39 / 0
1.9.24 39 / 0
1.9.23 39 / 0
Showing 100 of 125 Next page →

v2.0.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.60

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.50

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.49

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.48

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.47

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.63

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.62

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.60

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.49

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.47

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.46

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.