@plusscommunities/pluss-core-web
Core extension package for Pluss Communities platform
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Consistent with adding a new UI feature module, no malicious indicators. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Stale publisher change, 1778d live on npm, trusted publisher track record. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Same long-standing publisher, consistent with legitimate account continuity. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): jquery/react-dropzone are common, legitimate front-end deps fitting package purpose. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes canvas image data URL (strips data:image prefix); not a payload-hiding pattern. | ai |
Versions (showing 80 of 80)
| Version | Deps | Published |
|---|---|---|
| 1.6.18 | 1 / 11 | |
| 1.6.17 | 1 / 11 | |
| 1.6.16 | 1 / 11 | |
| 1.6.14 | 1 / 11 | |
| 1.6.13 | 1 / 11 | |
| 1.6.9 | 1 / 11 | |
| 1.6.8 | 1 / 11 | |
| 1.6.7 | 1 / 11 | |
| 1.6.6 | 1 / 11 | |
| 1.6.5 | 1 / 11 | |
| 1.6.2 | 1 / 11 | |
| 1.5.1 | 1 / 11 | |
| 1.5.0 | 1 / 11 | |
| 1.4.37 | 1 / 11 | |
| 1.4.36 | 14 / 11 | |
| 1.4.35 | 14 / 11 | |
| 1.4.34 | 14 / 11 | |
| 1.4.33 | 14 / 11 | |
| 1.4.32 | 14 / 11 | |
| 1.4.31 | 14 / 11 | |
| 1.4.30 | 14 / 11 | |
| 1.4.29 | 14 / 11 | |
| 1.4.28 | 14 / 11 | |
| 1.4.27 | 14 / 11 | |
| 1.4.26 | 14 / 11 | |
| 1.4.25 | 14 / 11 | |
| 1.4.24 | 14 / 11 | |
| 1.4.23 | 14 / 11 | |
| 1.4.22 | 14 / 11 | |
| 1.4.21 | 14 / 11 | |
| 1.4.20 | 11 / 11 | |
| 1.4.19 | 11 / 11 | |
| 1.4.18 | 11 / 11 | |
| 1.4.17 | 11 / 11 | |
| 1.4.12 | 11 / 11 | |
| 1.4.11 | 11 / 11 | |
| 1.4.10 | 11 / 11 | |
| 1.4.9 | 11 / 11 | |
| 1.4.5 | 11 / 11 | |
| 1.4.4 | 11 / 11 | |
| 1.4.3 | 11 / 11 | |
| 1.4.2 | 11 / 11 | |
| 1.4.1 | 11 / 11 | |
| 1.4.0 | 11 / 11 | |
| 1.3.1 | 11 / 11 | |
| 1.2.11 | 10 / 11 | |
| 1.2.10 | 10 / 11 | |
| 1.2.9 | 10 / 11 | |
| 1.2.8 | 10 / 11 | |
| 1.2.7 | 10 / 11 | |
| 1.2.6 | 10 / 11 | |
| 1.2.5 | 10 / 11 | |
| 1.2.4 | 10 / 11 | |
| 1.2.3 | 10 / 11 | |
| 1.2.2 | 10 / 11 | |
| 1.2.1 | 10 / 11 | |
| 1.2.0 | 10 / 11 | |
| 1.1.15 | 10 / 11 | |
| 1.1.14 | 10 / 11 | |
| 1.1.13 | 10 / 11 | |
| 1.1.12 | 10 / 11 | |
| 1.1.11 | 10 / 11 | |
| 1.1.10 | 10 / 11 | |
| 1.1.9 | 10 / 11 | |
| 1.1.8 | 10 / 11 | |
| 1.1.7 | 10 / 12 | |
| 1.1.6 | 10 / 11 | |
| 1.1.5 | 10 / 11 | |
| 1.1.4 | 10 / 11 | |
| 1.1.3 | 10 / 11 | |
| 1.1.2 | 10 / 11 | |
| 1.1.1 | 10 / 11 | |
| 1.0.7 | 10 / 11 | |
| 1.0.6 | 10 / 11 | |
| 1.0.5 | 8 / 11 | |
| 1.0.4 | 8 / 11 | |
| 1.0.3 | 8 / 11 | |
| 1.0.2 | 8 / 11 | |
| 1.0.1 | 8 / 11 | |
| 1.0.0 | 8 / 11 |
v1.6.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.31
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2024-01-30. It has since remained available on npm for 904 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.30
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-11-20. It has since remained available on npm for 975 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.29
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-11-15. It has since remained available on npm for 980 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.28
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-11-15. It has since remained available on npm for 980 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.27
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-10-05. It has since remained available on npm for 1021 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.26
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-08-31. It has since remained available on npm for 1057 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.25
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-08-25. It has since remained available on npm for 1062 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.24
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-07-14. It has since remained available on npm for 1104 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.23
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-06-20. It has since remained available on npm for 1128 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.22
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-05-30. It has since remained available on npm for 1149 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.21
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-05-26. It has since remained available on npm for 1153 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.20
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-05-24. It has since remained available on npm for 1156 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.19
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-05-19. It has since remained available on npm for 1160 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.18
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-05-12. It has since remained available on npm for 1167 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.17
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2023-03-08. It has since remained available on npm for 1232 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-09-29. It has since remained available on npm for 1392 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.11
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-08-31. It has since remained available on npm for 1421 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-08-31. It has since remained available on npm for 1421 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.9
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-07-20. It has since remained available on npm for 1463 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-05-17. It has since remained available on npm for 1528 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-05-16. It has since remained available on npm for 1528 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-05-10. It has since remained available on npm for 1534 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.11
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-01-14. It has since remained available on npm for 1650 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.10
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2022-01-06. It has since remained available on npm for 1658 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.9
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-12-14. It has since remained available on npm for 1681 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.5
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-11-25. It has since remained available on npm for 1700 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.15
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-11-11. It has since remained available on npm for 1714 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.6
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-10-07. It has since remained available on npm for 1749 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.5
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-09-22. It has since remained available on npm for 1764 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.4
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-09-22. It has since remained available on npm for 1764 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.3
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-09-22. It has since remained available on npm for 1764 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
2 findingsThis version was published by a different npm account (pluss-thor) than the most recent previously approved version (pluss_ps) on 2021-09-08. It has since remained available on npm for 1778 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.