@paypal/sdk-client
Shared config between PayPal/Braintree.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:paypal-sdk-constants | AI (dependencies): First-party PayPal-maintained constants package. | ai | |
| source-diff | net-exec-file:server/meta.test.js | AI (source-diff): Test file exercising base64-encoded SDK config parsing; no real network/exec payload. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party @krakenjs packages used by PayPal SDKs. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same historical transition, no new takeover signal. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Long-stable publisher transition, unchanged from prior approved versions. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Publisher change is 1732 days stale, inconsistent with takeover. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes sdkMeta token with subsequent URL validation; documented PayPal SDK metadata pattern. | ai | |
| phantom-deps | phantom-dep:bowser | AI (phantom-deps): bowser is a declared runtime dependency; phantom-dep heuristic false positive for this package. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() appears only in test files (meta.test.js), not in production/runtime code. | ai |
Versions (showing 100 of 159)
| Version | Deps | Published |
|---|---|---|
| 4.0.204 | 7 / 22 | |
| 4.0.203 | 7 / 22 | |
| 4.0.202 | 7 / 22 | |
| 4.0.201 | 7 / 22 | |
| 4.0.200 | 7 / 22 | |
| 4.0.199 | 7 / 22 | |
| 4.0.198 | 7 / 22 | |
| 4.0.197 | 7 / 22 | |
| 4.0.196 | 7 / 22 | |
| 4.0.195 | 7 / 22 | |
| 4.0.194 | 7 / 21 | |
| 4.0.193 | 7 / 21 | |
| 4.0.192 | 7 / 21 | |
| 4.0.191 | 7 / 21 | |
| 4.0.190 | 7 / 21 | |
| 4.0.189 | 7 / 21 | |
| 4.0.188 | 7 / 21 | |
| 4.0.187 | 7 / 21 | |
| 4.0.186 | 7 / 21 | |
| 4.0.185 | 7 / 20 | |
| 4.0.184 | 7 / 20 | |
| 4.0.183 | 7 / 20 | |
| 4.0.182 | 7 / 20 | |
| 4.0.181 | 7 / 20 | |
| 4.0.180 | 7 / 15 | |
| 4.0.179 | 7 / 15 | |
| 4.0.178 | 7 / 15 | |
| 4.0.177 | 7 / 15 | |
| 4.0.176 | 7 / 15 | |
| 4.0.175 | 7 / 15 | |
| 4.0.174 | 7 / 15 | |
| 4.0.173 | 7 / 15 | |
| 4.0.172 | 7 / 15 | |
| 4.0.171 | 7 / 15 | |
| 4.0.170 | 7 / 15 | |
| 4.0.169 | 7 / 15 | |
| 4.0.168 | 7 / 9 | |
| 4.0.167 | 7 / 9 | |
| 4.0.166 | 7 / 9 | |
| 4.0.165 | 6 / 9 | |
| 4.0.164 | 6 / 9 | |
| 4.0.163 | 6 / 9 | |
| 4.0.162 | 6 / 9 | |
| 4.0.161 | 6 / 9 | |
| 4.0.160 | 6 / 9 | |
| 4.0.159 | 6 / 9 | |
| 4.0.158 | 6 / 9 | |
| 4.0.156 | 6 / 9 | |
| 4.0.155 | 6 / 9 | |
| 4.0.154 | 6 / 9 | |
| 4.0.153 | 6 / 9 | |
| 4.0.152 | 6 / 9 | |
| 4.0.151 | 6 / 9 | |
| 4.0.150 | 6 / 9 | |
| 4.0.149 | 6 / 9 | |
| 4.0.148 | 6 / 9 | |
| 4.0.147 | 6 / 9 | |
| 4.0.146 | 6 / 9 | |
| 4.0.145 | 6 / 9 | |
| 4.0.144 | 6 / 9 | |
| 4.0.143 | 6 / 9 | |
| 4.0.142 | 6 / 9 | |
| 4.0.141 | 6 / 9 | |
| 4.0.140 | 6 / 9 | |
| 4.0.139 | 6 / 9 | |
| 4.0.138 | 6 / 9 | |
| 4.0.137 | 6 / 9 | |
| 4.0.136 | 6 / 9 | |
| 4.0.135 | 6 / 9 | |
| 4.0.134 | 6 / 9 | |
| 4.0.133 | 6 / 9 | |
| 4.0.132 | 6 / 9 | |
| 4.0.131 | 6 / 9 | |
| 4.0.130 | 6 / 9 | |
| 4.0.129 | 6 / 9 | |
| 4.0.128 | 6 / 9 | |
| 4.0.127 | 6 / 9 | |
| 4.0.126 | 6 / 9 | |
| 4.0.125 | 6 / 9 | |
| 4.0.124 | 6 / 9 | |
| 4.0.123 | 6 / 9 | |
| 4.0.122 | 6 / 9 | |
| 4.0.121 | 6 / 9 | |
| 4.0.120 | 6 / 9 | |
| 4.0.119 | 6 / 9 | |
| 4.0.118 | 6 / 9 | |
| 4.0.117 | 6 / 9 | |
| 4.0.116 | 6 / 9 | |
| 4.0.115 | 6 / 9 | |
| 4.0.114 | 6 / 9 | |
| 4.0.113 | 6 / 9 | |
| 4.0.112 | 6 / 9 | |
| 4.0.111 | 6 / 9 | |
| 4.0.110 | 6 / 9 | |
| 4.0.109 | 6 / 9 | |
| 4.0.108 | 6 / 9 | |
| 4.0.107 | 6 / 9 | |
| 4.0.106 | 6 / 9 | |
| 4.0.105 | 6 / 9 | |
| 4.0.103 | 6 / 9 |
v4.0.197
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.196
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.195
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.194
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.193
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.192
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.191
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.190
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.189
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.188
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.187
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2024-04-17. It has since remained available on npm for 829 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.186
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2024-04-17. It has since remained available on npm for 829 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.185
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2024-03-15. It has since remained available on npm for 862 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.184
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2024-03-12. It has since remained available on npm for 865 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.183
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2024-03-06. It has since remained available on npm for 871 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.182
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2024-02-22. It has since remained available on npm for 884 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.181
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2024-02-15. It has since remained available on npm for 891 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.180
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-12-19. It has since remained available on npm for 949 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.179
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-12-15. It has since remained available on npm for 953 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.178
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-12-05. It has since remained available on npm for 963 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.177
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-09-18. It has since remained available on npm for 1041 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.176
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-08-09. It has since remained available on npm for 1081 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.175
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-06-21. It has since remained available on npm for 1130 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.174
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-06-15. It has since remained available on npm for 1136 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.173
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-06-13. It has since remained available on npm for 1138 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.172
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-06-12. It has since remained available on npm for 1139 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.171
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-05-23. It has since remained available on npm for 1159 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.170
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-05-16. It has since remained available on npm for 1166 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.169
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2023-01-09. It has since remained available on npm for 1293 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.168
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2022-06-21. It has since remained available on npm for 1495 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.167
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2022-05-09. It has since remained available on npm for 1538 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.166
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2022-04-04. It has since remained available on npm for 1573 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.165
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2022-03-01. It has since remained available on npm for 1607 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.164
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2022-02-07. It has since remained available on npm for 1629 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.163
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2022-01-25. It has since remained available on npm for 1642 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.162
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2021-11-17. It has since remained available on npm for 1711 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.161
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2021-11-09. It has since remained available on npm for 1719 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.160
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2021-11-01. It has since remained available on npm for 1727 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.159
2 findingsThis version was published by a different npm account (sdk-integrations-npm) than the most recent previously approved version (bluepnume) on 2021-10-27. It has since remained available on npm for 1732 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.158
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bluepnume) than the most recent previously approved version (gregjopa) on 2021-07-16, but bluepnume is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.156
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.155
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.154
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.153
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.152
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.151
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.150
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.149
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gregjopa) than the most recent previously approved version (amyegan) on 2021-03-17, but gregjopa is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.148
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (amyegan) than the most recent previously approved version (bluepnume) on 2021-03-17, but amyegan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.147
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mstuart) than the most recent previously approved version (bluepnume) on 2021-02-09, but mstuart is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.146
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bluepnume) than the most recent previously approved version (gregjopa) on 2021-02-02, but bluepnume is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.145
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mnicpt) than the most recent previously approved version (gregjopa) on 2021-02-02, but mnicpt is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.144
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gregjopa) than the most recent previously approved version (bluepnume) on 2020-12-15, but gregjopa is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.143
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gregjopa) than the most recent previously approved version (bluepnume) on 2020-12-09, but gregjopa is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.142
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.141
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.140
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.139
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.138
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.137
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.136
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.135
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.134
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.133
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.132
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.131
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bluepnume) than the most recent previously approved version (elizabethmv) on 2020-09-01, but bluepnume is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.130
2 findingsThis version was published by a different npm account (elizabethmv) than the most recent previously approved version (bluepnume) on 2020-08-26. It has since remained available on npm for 2159 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.129
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.128
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.127
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.126
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.125
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.124
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.123
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.122
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.121
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.120
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.119
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.118
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.117
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.116
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.115
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.114
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.113
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.112
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.111
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.110
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.109
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.108
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.107
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.106
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.105
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.103
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.