@open-tender/types
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer, no behavioral change; benign publish-env variance. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer matches known team member pattern, no other risk signals. | ai |
Versions (showing 51 of 122)
| Version | Deps | Published |
|---|---|---|
| 0.4.178 | 0 / 17 | |
| 0.4.177 | 0 / 17 | |
| 0.4.176 | 0 / 17 | |
| 0.4.175 | 0 / 17 | |
| 0.4.173 | 0 / 17 | |
| 0.4.172 | 0 / 17 | |
| 0.4.171 | 0 / 17 | |
| 0.4.170 | 0 / 17 | |
| 0.4.169 | 0 / 17 | |
| 0.4.168 | 0 / 17 | |
| 0.4.167 | 0 / 17 | |
| 0.4.166 | 0 / 17 | |
| 0.4.165 | 0 / 17 | |
| 0.4.164 | 0 / 17 | |
| 0.4.163 | 0 / 17 | |
| 0.4.162 | 0 / 17 | |
| 0.4.161 | 0 / 17 | |
| 0.4.160 | 0 / 17 | |
| 0.4.159 | 0 / 17 | |
| 0.4.158 | 0 / 17 | |
| 0.4.157 | 0 / 17 | |
| 0.4.156 | 0 / 17 | |
| 0.4.155 | 0 / 17 | |
| 0.4.154 | 0 / 17 | |
| 0.4.153 | 0 / 17 | |
| 0.4.152 | 0 / 17 | |
| 0.4.151 | 0 / 17 | |
| 0.4.150 | 0 / 17 | |
| 0.4.149 | 0 / 17 | |
| 0.4.148 | 0 / 17 | |
| 0.4.147 | 0 / 17 | |
| 0.4.146 | 0 / 17 | |
| 0.4.145 | 0 / 17 | |
| 0.4.144 | 0 / 17 | |
| 0.4.143 | 0 / 17 | |
| 0.4.142 | 0 / 17 | |
| 0.4.141 | 0 / 17 | |
| 0.4.140 | 0 / 17 | |
| 0.4.139 | 0 / 17 | |
| 0.4.138 | 0 / 17 | |
| 0.4.137 | 0 / 17 | |
| 0.4.136 | 0 / 17 | |
| 0.4.135 | 0 / 17 | |
| 0.4.134 | 0 / 17 | |
| 0.4.133 | 0 / 17 | |
| 0.4.132 | 0 / 17 | |
| 0.4.131 | 0 / 17 | |
| 0.4.130 | 0 / 17 | |
| 0.4.128 | 0 / 17 | |
| 0.4.127 | 0 / 17 | |
| 0.4.126 | 0 / 17 |
v0.4.176
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.175
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (shady.abdelaziz.farahat) than the most recent previously approved version (nasser_md) on 2026-04-09, but shady.abdelaziz.farahat is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.171
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.170
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (shady.abdelaziz.farahat) than the most recent previously approved version (nasser_md) on 2025-10-22, but shady.abdelaziz.farahat is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.169
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.168
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.167
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.166
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.165
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.164
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.163
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.162
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.161
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (shady.abdelaziz.farahat) than the most recent previously approved version (nasser_md) on 2025-09-03, but shady.abdelaziz.farahat is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.160
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.159
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.158
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (shady.abdelaziz.farahat) than the most recent previously approved version (nasser_md) on 2025-08-20, but shady.abdelaziz.farahat is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.157
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.156
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.155
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.154
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.153
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.152
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.151
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.150
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.149
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.148
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.147
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.146
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.145
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.144
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-03-20, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.143
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-03-20, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.142
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.141
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-02-24, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.140
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-02-24, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.139
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.138
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-02-14, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.137
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-02-06, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.136
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-02-04, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.135
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.134
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-01-30, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.133
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-01-30, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.132
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vaulis11.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vaulis11) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-01-24, but vaulis11 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.131
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vaulis11.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vaulis11) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-01-24, but vaulis11 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.130
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vaulis11.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vaulis11) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-01-14, but vaulis11 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.128
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.127
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nasser_md.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nasser_md) than the most recent previously approved version (shady.abdelaziz.farahat) on 2025-01-02, but nasser_md is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.126
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: vaulis11.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vaulis11) than the most recent previously approved version (shady.abdelaziz.farahat) on 2024-12-24, but vaulis11 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.