@qrvey/utils
Helper, Utils for all Qrvey Projects
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed-stale | AI (provenance): Old, long-standing publisher change with no takeover pattern; consistent across many approved versions. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Local publish helper script, not shipped runtime behavior. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): Dot-path property getter eval, standard lodash-like utility pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): xss, tslib, @stencil/store are all established, well-known packages with no malicious history. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Qrvey org team rotation; new maintainers are within the same organization. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Qrvey org team rotation; removal consistent with internal team changes. | ai |
Versions (showing 76 of 76)
| Version | Deps | Published |
|---|---|---|
| 1.112.2 | 3 / 16 | |
| 1.18.6 | 6 / 26 | |
| 1.18.5 | 6 / 26 | |
| 1.18.4 | 6 / 26 | |
| 1.18.3 | 6 / 26 | |
| 1.18.2 | 6 / 26 | |
| 1.18.1 | 6 / 26 | |
| 1.18.0 | 6 / 26 | |
| 1.17.6 | 6 / 26 | |
| 1.17.5 | 6 / 26 | |
| 1.17.4 | 6 / 26 | |
| 1.17.3 | 6 / 26 | |
| 1.17.2 | 6 / 26 | |
| 1.17.1 | 6 / 26 | |
| 1.17.0 | 6 / 26 | |
| 1.15.0 | 5 / 19 | |
| 1.14.0 | 4 / 19 | |
| 1.13.1 | 4 / 19 | |
| 1.13.0 | 4 / 19 | |
| 1.12.23 | 3 / 16 | |
| 1.12.1 | 3 / 16 | |
| 1.12.0 | 3 / 16 | |
| 1.11.4 | 3 / 16 | |
| 1.11.3 | 3 / 16 | |
| 1.11.2 | 3 / 16 | |
| 1.11.1 | 3 / 16 | |
| 1.11.0 | 3 / 16 | |
| 1.10.1 | 3 / 15 | |
| 1.10.0 | 3 / 15 | |
| 1.9.0 | 3 / 15 | |
| 1.8.1 | 3 / 15 | |
| 1.8.0 | 3 / 15 | |
| 1.7.1 | 3 / 15 | |
| 1.7.0 | 3 / 15 | |
| 1.6.0 | 3 / 15 | |
| 1.5.0 | 3 / 14 | |
| 1.4.9 | 3 / 14 | |
| 1.4.8 | 3 / 14 | |
| 1.4.7 | 3 / 13 | |
| 1.4.6 | 3 / 13 | |
| 1.4.5 | 3 / 13 | |
| 1.4.4 | 3 / 13 | |
| 1.4.3 | 3 / 13 | |
| 1.4.2 | 3 / 13 | |
| 1.4.1 | 3 / 13 | |
| 1.4.0 | 3 / 13 | |
| 1.1.8 | 2 / 10 | |
| 1.1.7 | 2 / 10 | |
| 1.1.6 | 2 / 10 | |
| 1.1.5 | 2 / 10 | |
| 1.1.4 | 2 / 10 | |
| 1.1.3 | 2 / 10 | |
| 1.1.2 | 2 / 10 | |
| 1.1.1 | 2 / 10 | |
| 1.1.0 | 2 / 7 | |
| 1.0.20 | 1 / 3 | |
| 1.0.19 | 1 / 2 | |
| 1.0.18 | 0 / 2 | |
| 1.0.17 | 0 / 2 | |
| 1.0.16 | 0 / 2 | |
| 1.0.15 | 0 / 2 | |
| 1.0.14 | 0 / 2 | |
| 1.0.13 | 0 / 2 | |
| 1.0.12 | 0 / 2 | |
| 1.0.11 | 0 / 2 | |
| 1.0.10 | 0 / 2 | |
| 1.0.9 | 0 / 2 | |
| 1.0.8 | 0 / 2 | |
| 1.0.7 | 0 / 2 | |
| 1.0.6 | 0 / 2 | |
| 1.0.5 | 0 / 2 | |
| 1.0.4 | 0 / 2 | |
| 1.0.3 | 0 / 2 | |
| 1.0.2 | 0 / 2 | |
| 1.0.1 | 0 / 2 | |
| 1.0.0 | 0 / 2 |
v1.112.2
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2024-02-19. It has since remained available on npm for 883 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mario.vasco) than the most recent previously approved version (jose.gonzalez.qrvey) on 2025-03-31, but mario.vasco is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2024-04-08. It has since remained available on npm for 835 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.1
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2024-02-09. It has since remained available on npm for 893 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2024-01-15. It has since remained available on npm for 918 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.4
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2024-02-19. It has since remained available on npm for 883 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.3
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2024-02-09. It has since remained available on npm for 893 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.2
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2023-10-19. It has since remained available on npm for 1006 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.1
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2023-07-18. It has since remained available on npm for 1099 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2023-07-12. It has since remained available on npm for 1105 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.1
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2023-04-10. It has since remained available on npm for 1198 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2023-03-24. It has since remained available on npm for 1215 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2023-01-25. It has since remained available on npm for 1273 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.1
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-12-06. It has since remained available on npm for 1323 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-12-06. It has since remained available on npm for 1323 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.1
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-10-24. It has since remained available on npm for 1366 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-10-21. It has since remained available on npm for 1369 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-10-05. It has since remained available on npm for 1385 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-08-24. It has since remained available on npm for 1427 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.9
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-10-05. It has since remained available on npm for 1385 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-09-26. It has since remained available on npm for 1394 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-09-14. It has since remained available on npm for 1406 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-07-28. It has since remained available on npm for 1454 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-07-01. It has since remained available on npm for 1481 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-06-30. It has since remained available on npm for 1482 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-06-30. It has since remained available on npm for 1482 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-06-30. It has since remained available on npm for 1483 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-06-29. It has since remained available on npm for 1483 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2022-06-23. It has since remained available on npm for 1489 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.8
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-10-12. It has since remained available on npm for 1743 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.7
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-10-11. It has since remained available on npm for 1744 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.6
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-09-28. It has since remained available on npm for 1757 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.5
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-09-27. It has since remained available on npm for 1758 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.4
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-09-23. It has since remained available on npm for 1762 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.3
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-09-23. It has since remained available on npm for 1762 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-09-17. It has since remained available on npm for 1768 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-09-14. It has since remained available on npm for 1771 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
2 findingsThis version was published by a different npm account (jose.gonzalez.qrvey) than the most recent previously approved version (david.seija) on 2021-09-13. It has since remained available on npm for 1772 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (david.seija) than the most recent previously approved version (emirpolo) on 2020-12-09, but david.seija is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (emirpolo) than the most recent previously approved version (david.seija) on 2020-12-05, but emirpolo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (david.seija) than the most recent previously approved version (emirpolo) on 2020-11-30, but david.seija is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (emirpolo) than the most recent previously approved version (david.seija) on 2020-11-24, but emirpolo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (emirpolo) than the most recent previously approved version (david.seija) on 2020-11-20, but emirpolo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.