@openglobus/og
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @openglobus/og is a legitimate WebGL globe library; short suffix 'og' coincidentally close to 'pg' but no impersonation. | ai | |
| typosquat | typosquat.levenshtein:koa | AI (typosquat): Same scoped-package false positive; no relation to koa. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Same scoped-package false positive; no relation to got. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Same scoped-package false positive; no relation to qs. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Same scoped-package false positive; no relation to joi. | ai | |
| typosquat | typosquat.levenshtein:zod | AI (typosquat): Same scoped-package false positive; no relation to zod. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 0.28.7 | 0 / 24 | |
| 0.28.6 | 0 / 24 | |
| 0.28.5 | 0 / 24 | |
| 0.28.4 | 0 / 24 | |
| 0.28.3 | 0 / 24 | |
| 0.28.2 | 0 / 24 | |
| 0.28.1 | 0 / 24 | |
| 0.28.0 | 0 / 24 | |
| 0.27.24 | 0 / 24 | |
| 0.27.23 | 0 / 24 | |
| 0.27.22 | 0 / 24 | |
| 0.27.21 | 0 / 24 | |
| 0.25.5 | 0 / 35 | |
| 0.25.4 | 0 / 35 | |
| 0.25.3 | 0 / 35 | |
| 0.25.2 | 0 / 35 | |
| 0.25.1 | 0 / 35 |
v0.28.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.25.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.