@pisell/utils
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Scoped internal org utility package (@pisell); missing README/repo/keywords is consistent with private/internal tooling, not spam or malware. 78 versions over 1033 days confirms legitimate ongoing use. | ai | |
| dependencies | unvetted-dep:detectincognitojs | AI (dependencies): detectincognitojs is a legitimate incognito-mode detection library; its use in a utility package alongside Firebase is plausible and not a security concern. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 3.0.2 | 3 / 3 | |
| 1.0.70 | 3 / 3 | |
| 1.0.52 | 3 / 3 | |
| 1.0.51 | 3 / 3 | |
| 1.0.50 | 3 / 3 | |
| 1.0.49 | 3 / 3 | |
| 1.0.48 | 3 / 3 | |
| 1.0.47 | 3 / 3 | |
| 1.0.46 | 3 / 3 | |
| 1.0.45 | 3 / 3 | |
| 1.0.44 | 3 / 3 | |
| 1.0.43 | 3 / 3 | |
| 1.0.42 | 3 / 3 | |
| 1.0.41 | 3 / 3 | |
| 1.0.40 | 3 / 3 | |
| 1.0.39 | 3 / 3 | |
| 1.0.38 | 3 / 3 | |
| 1.0.37 | 3 / 3 | |
| 1.0.36 | 3 / 3 | |
| 1.0.35 | 3 / 3 | |
| 1.0.34 | 3 / 3 | |
| 1.0.33 | 2 / 3 | |
| 1.0.32 | 2 / 3 | |
| 1.0.31 | 2 / 3 | |
| 1.0.30 | 2 / 3 | |
| 1.0.29 | 2 / 3 | |
| 1.0.28 | 2 / 3 | |
| 1.0.27 | 2 / 3 | |
| 1.0.26 | 2 / 3 | |
| 1.0.25 | 2 / 3 | |
| 1.0.24 | 2 / 3 | |
| 1.0.5 | 0 / 2 | |
| 1.0.2 | 0 / 2 | |
| 1.0.1 | 0 / 1 |
v1.0.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.39
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (zsj1037797769) on 2024-09-05, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.36
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (zsj1037797769) on 2024-09-02, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.33
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (zhiwei.wang) on 2024-08-18, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.32
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (zhiwei.wang) on 2024-08-18, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.30
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (zhiwei.wang) on 2024-08-16, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.29
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (zsj1037797769) on 2024-08-12, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.