← Home

@pisell/pisellos

一个可扩展的前端模块化SDK框架,支持插件系统

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

wang_hanzsj1037797769zhiwei.wangyaoxiaojialarry_ranhejunxiangfeng.xueah-scjinglin.tan

Keywords

frontendsdkframeworkmodularplugin-system

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/modules/ScanOrderLogger/providers/feishu.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/solution/VenueBooking/index.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/solution/ScanOrder/index.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/ScanOrderLogger/index.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/SalesSummary/index.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/Quotation/index.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/OpenData/index.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/ScanOrderLogger/providers/grafana.js AI (source-diff): Babel-compiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/SurchargeList/index.js AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/solution/BookingTicket/utils/scan/applyGlobalScan.js AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/solution/BookingTicket/utils/scan/cloudSearch.js AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/Payment/eftpos.js AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/solution/BookingTicket/utils/scan/handleScan.js AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/BookingContext/index.js AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/modules/Customer/index.js AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/server/modules/resource/index.js AI (source-diff): Bundled build output, not malicious obfuscation. ai
source-diff obfuscated-file:dist/solution/Sales/index.js AI (source-diff): Bundled build output, not malicious obfuscation. ai
source-diff obfuscated-file:dist/server/modules/schedule/index.js AI (source-diff): Bundled build output, not malicious obfuscation. ai
source-diff obfuscated-file:dist/server/modules/products/index.js AI (source-diff): Bundled build output, not malicious obfuscation. ai
source-diff obfuscated-file:dist/server/modules/quotation/index.js AI (source-diff): Bundled build output, not malicious obfuscation. ai
source-diff obfuscated-file:dist/server/modules/menu/index.js AI (source-diff): Bundled build output, not malicious obfuscation. ai
source-diff obfuscated-file:dist/server/modules/order/index.js AI (source-diff): Bundled build output, not malicious obfuscation. ai
source-diff obfuscated-file:dist/modules/Holder/index.js AI (source-diff): Babel-transpiled helper boilerplate, not true obfuscation; consistent with prior bundled dist files. ai
publish-pattern rapid-publish AI (publish-pattern): Frequent releases are normal cadence for this actively-maintained SDK (1272 versions). ai
source-diff obfuscated-file:dist/utils/payment-number.js AI (source-diff): father/Babel minified bundler output (regenerator-runtime preamble), not true obfuscation; benign payment-math helper. ai
source-diff obfuscated-file:dist/server/index.js AI (source-diff): Babel/regenerator bundler output, not true obfuscation; large SDK build artifact. ai
source-diff obfuscated-file:dist/modules/Payment/cash.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/solution/Checkout/index.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
semgrep semgrep:new-function-constructor AI (semgrep): StrategyEngine rules-expression evaluator; standard template/rules-engine use, no hostile target. ai
semgrep semgrep:eval-usage AI (semgrep): eval inside SimpleWindow setTimeout/setInterval polyfill emulating browser string-handler spec; benign. ai
source-diff large-new-source-files AI (source-diff): Legit monorepo SDK adding solution bundles; mass file additions are normal release pattern for this package. ai
phantom-deps phantom-dep:@changesets/cli AI (phantom-deps): Build/release tooling mistakenly listed as runtime dep; not a security issue for this package. ai
phantom-deps phantom-dep:@types/lodash-es AI (phantom-deps): TypeScript type package listed as runtime dep; not a security issue for this package. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() in a Proxy handler is standard reactive state management pattern (similar to Vue 3 reactivity), not obfuscation. Stable for this package. ai

Versions (showing 51 of 382)

View all versions
Version Deps Published
3.0.93 5 / 11
3.0.92 5 / 11
3.0.91 5 / 11
3.0.90 5 / 11
3.0.89 5 / 11
3.0.88 5 / 11
3.0.87 5 / 11
3.0.86 5 / 11
3.0.85 5 / 11
3.0.84 5 / 11
3.0.83 5 / 11
3.0.79 5 / 11
3.0.73 5 / 11
3.0.72 5 / 11
3.0.71 5 / 11
3.0.70 5 / 11
3.0.69 5 / 11
3.0.68 5 / 11
3.0.67 5 / 11
2.3.37 5 / 12
2.3.36 5 / 12
2.3.35 5 / 12
2.3.34 5 / 12
2.3.33 5 / 12
2.3.32 5 / 12
2.3.31 5 / 12
2.3.30 5 / 12
2.3.29 5 / 12
2.3.28 5 / 12
2.3.27 5 / 12
2.3.26 5 / 12
2.3.22 5 / 12
2.3.21 5 / 12
2.3.20 5 / 12
2.3.19 5 / 12
2.3.18 5 / 12
2.3.17 5 / 12
2.3.16 5 / 12
2.3.15 5 / 12
2.3.14 5 / 12
2.3.13 5 / 12
2.3.12 5 / 12
2.3.11 5 / 12
2.3.10 5 / 12
2.3.9 5 / 12
2.3.8 5 / 12
2.3.7 5 / 12
2.3.6 5 / 12
2.2.271 5 / 12
2.2.270 5 / 12
2.2.266 5 / 12

v3.0.93

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.92

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.91

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.90

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-05-14, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-05-14, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.0.88

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-05-06, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-05-06, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.0.83

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.30

2 findings
HIGH New obfuscated file: dist/utils/payment-number.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.29

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → zsj1037797769 (on 2026-07-13, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-13, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.28

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-11, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-11, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.26

16 findings
HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/BookingContext/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SurchargeList/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/floor-plan/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/menu/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/order/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/payment/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/products/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/quotation/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/resource/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/server/modules/schedule/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BaseSales/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/Sales/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-11, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-11, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.22

10 findings
HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/handleScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/BookingContext/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Customer/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SurchargeList/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → zsj1037797769 (on 2026-07-09, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-09, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.21

9 findings
HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/handleScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/BookingContext/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Customer/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SurchargeList/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.20

10 findings
HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/handleScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/BookingContext/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Customer/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SurchargeList/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → zsj1037797769 (on 2026-07-07, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-07, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.19

10 findings
HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/handleScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/BookingContext/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Customer/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SurchargeList/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → zsj1037797769 (on 2026-07-07, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-07, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.18

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-06, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-06, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.17

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-05, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-05, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.16

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-04, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-04, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.15

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.14

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.13

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.12

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.11

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.10

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.9

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.8

7 findings
HIGH Large number of new source files: 664 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-02, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-02, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.7

7 findings
HIGH Large number of new source files: 660 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 660 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-01, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-01, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.6

7 findings
HIGH Large number of new source files: 660 source-diff

[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 660 new source files. A suddenly much larger package could indicate bundled/injected code.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/applyGlobalScan.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/cash.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/solution/BookingTicket/utils/scan/cloudSearch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Payment/eftpos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-06-30, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-06-30, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.271

7 findings
HIGH New obfuscated file: dist/modules/ScanOrderLogger/providers/feishu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/ScanOrderLogger/providers/grafana.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/OpenData/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Quotation/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SalesSummary/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: wang_han → zsj1037797769 (on 2026-07-17, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (wang_han) on 2026-07-17, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.270

7 findings
HIGH New obfuscated file: dist/modules/ScanOrderLogger/providers/feishu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/ScanOrderLogger/providers/grafana.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/OpenData/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Quotation/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SalesSummary/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: wang_han → zsj1037797769 (on 2026-07-16, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (wang_han) on 2026-07-16, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.266

7 findings
HIGH New obfuscated file: dist/modules/ScanOrderLogger/providers/feishu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/ScanOrderLogger/providers/grafana.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/OpenData/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/Quotation/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/modules/SalesSummary/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: wang_han → zsj1037797769 (on 2026-07-16, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (wang_han) on 2026-07-16, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.