@promptbook/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Monorepo-style package with routine bulk regeneration across versions. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads fs/promises dynamically for isomorphic node/browser support, not arbitrary user input. | ai | |
| email-domain | unclaimed-email:hejny.org | AI (email-domain): Long-standing trusted publisher; contact email domain lapse is not a behavior signal. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are mainstream LLM SDKs aligned with package purpose. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() used in a Proxy handler for property delegation; standard JS pattern, not obfuscation. | ai | |
| phantom-deps | phantom-dep:bottleneck | AI (phantom-deps): Stable FP; bottleneck is a declared dep in this package. | ai | |
| phantom-deps | phantom-dep:waitasecond | AI (phantom-deps): Stable FP; waitasecond is a declared dep in this package. | ai | |
| phantom-deps | phantom-dep:crypto-js | AI (phantom-deps): Stable FP; crypto-js is a declared dep in this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Monorepo package; zod declared as dep with override, phantom-dep is a stable FP. | ai | |
| phantom-deps | phantom-dep:colors | AI (phantom-deps): Stable FP for this package; declared dep used transitively. | ai | |
| phantom-deps | phantom-dep:crypto | AI (phantom-deps): Stable FP; crypto is a declared dep in this package. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Stable FP; dotenv is a declared dep in this package. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function() used for browser-environment detection idiom; standard pattern in cross-platform JS libraries. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() used in a sandboxed script-execution loop with a TODO to replace; consistent with the package's scripting-engine purpose. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @promptbook/core; Levenshtein match to 'cors' is a false positive with no brand confusion. | ai |
Versions (showing 100 of 186)
| Version | Deps | Published |
|---|---|---|
| 0.112.0 | 14 / 0 | |
| 0.110.0 | 12 / 0 | |
| 0.105.0 | 11 / 0 | |
| 0.104.0 | 11 / 0 | |
| 0.103.0 | 11 / 0 | |
| 0.102.0 | 8 / 0 | |
| 0.101.0 | 8 / 0 | |
| 0.100.2 | 8 / 0 | |
| 0.100.1 | 8 / 0 | |
| 0.100.0 | 8 / 0 | |
| 0.98.0 | 9 / 0 | |
| 0.95.0 | 9 / 0 | |
| 0.94.0 | 9 / 0 | |
| 0.93.0 | 9 / 0 | |
| 0.92.0 | 9 / 0 | |
| 0.89.0 | 9 / 0 | |
| 0.88.0 | 9 / 0 | |
| 0.86.31 | 9 / 0 | |
| 0.86.30 | 9 / 0 | |
| 0.86.22 | 9 / 0 | |
| 0.86.10 | 9 / 0 | |
| 0.86.8 | 9 / 0 | |
| 0.86.6 | 9 / 0 | |
| 0.86.5 | 9 / 0 | |
| 0.85.0 | 9 / 0 | |
| 0.84.0 | 7 / 0 | |
| 0.83.0 | 7 / 0 | |
| 0.82.0 | 7 / 0 | |
| 0.81.0 | 7 / 0 | |
| 0.80.0 | 8 / 0 | |
| 0.79.0 | 7 / 0 | |
| 0.78.4 | 7 / 0 | |
| 0.78.3 | 7 / 0 | |
| 0.78.2 | 7 / 0 | |
| 0.77.1 | 7 / 0 | |
| 0.77.0 | 7 / 0 | |
| 0.76.0 | 6 / 0 | |
| 0.75.10 | 6 / 0 | |
| 0.75.9 | 6 / 0 | |
| 0.75.8 | 6 / 0 | |
| 0.75.6 | 6 / 0 | |
| 0.75.5 | 6 / 0 | |
| 0.75.4 | 6 / 0 | |
| 0.75.3 | 6 / 0 | |
| 0.75.2 | 6 / 0 | |
| 0.75.1 | 6 / 0 | |
| 0.74.0 | 6 / 0 | |
| 0.73.0 | 6 / 0 | |
| 0.72.0 | 6 / 0 | |
| 0.69.6 | 5 / 0 | |
| 0.69.5 | 5 / 0 | |
| 0.69.3 | 5 / 0 | |
| 0.69.2 | 5 / 0 | |
| 0.69.1 | 5 / 0 | |
| 0.69.0 | 5 / 0 | |
| 0.68.5 | 4 / 0 | |
| 0.68.4 | 4 / 0 | |
| 0.68.3 | 4 / 0 | |
| 0.68.2 | 4 / 0 | |
| 0.68.0 | 4 / 0 | |
| 0.67.9 | 4 / 0 | |
| 0.67.8 | 3 / 0 | |
| 0.67.7 | 3 / 0 | |
| 0.67.6 | 3 / 0 | |
| 0.67.5 | 3 / 0 | |
| 0.67.4 | 3 / 0 | |
| 0.67.3 | 3 / 0 | |
| 0.67.2 | 3 / 0 | |
| 0.67.1 | 3 / 0 | |
| 0.67.0 | 3 / 0 | |
| 0.66.0 | 3 / 0 | |
| 0.65.0 | 8 / 0 | |
| 0.63.4 | 3 / 0 | |
| 0.63.3 | 3 / 0 | |
| 0.63.2 | 3 / 0 | |
| 0.63.1 | 3 / 0 | |
| 0.63.0 | 3 / 0 | |
| 0.62.1 | 3 / 0 | |
| 0.62.0 | 3 / 0 | |
| 0.61.0 | 3 / 0 | |
| 0.60.1 | 3 / 0 | |
| 0.60.0 | 3 / 0 | |
| 0.59.0 | 3 / 0 | |
| 0.58.0 | 3 / 0 | |
| 0.57.2 | 3 / 0 | |
| 0.57.1 | 3 / 0 | |
| 0.57.0 | 3 / 0 | |
| 0.56.0 | 3 / 0 | |
| 0.55.0 | 3 / 0 | |
| 0.54.1 | 3 / 0 | |
| 0.54.0 | 3 / 0 | |
| 0.53.0 | 3 / 0 | |
| 0.52.0 | 3 / 0 | |
| 0.51.0 | 2 / 0 | |
| 0.50.0 | 2 / 0 | |
| 0.49.1 | 2 / 0 | |
| 0.49.0 | 2 / 0 | |
| 0.48.0 | 1 / 0 | |
| 0.47.0 | 1 / 0 | |
| 0.46.0 | 1 / 0 |
v0.112.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.110.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.105.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.89.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.88.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.83.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.82.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.79.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.78.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.78.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.78.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.77.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.77.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.76.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.72.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.69.6
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.69.5
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.69.3
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.69.2
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.69.1
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.69.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.5
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.4
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.3
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.2
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.9
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.8
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.7
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.6
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.5
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.4
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.3
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.2
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.1
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.66.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.65.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.4
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.3
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.2
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.1
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.62.1
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.62.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.1
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.59.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.56.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.55.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.54.1
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.54.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.53.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.52.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.50.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.49.1
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.49.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.48.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.47.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.46.0
2 findingsMaintainer email '[email protected]' uses domain 'hejny.org' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.