@sasjs/core
Macros for SAS Application Developers
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped @sasjs/core package with 6yr history; name similarity to 'cors' is coincidental, not impersonation. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 4.67.1 | 0 / 0 | |
| 4.67.0 | 0 / 0 | |
| 4.66.4 | 0 / 0 | |
| 4.66.3 | 0 / 0 | |
| 4.66.2 | 0 / 0 | |
| 4.66.1 | 0 / 0 | |
| 4.66.0 | 0 / 0 | |
| 4.65.5 | 0 / 0 | |
| 4.65.4 | 0 / 0 | |
| 4.65.3 | 0 / 0 | |
| 4.65.2 | 0 / 0 | |
| 4.65.1 | 0 / 0 | |
| 4.65.0 | 0 / 0 | |
| 4.64.1 | 0 / 0 | |
| 4.64.0 | 0 / 0 | |
| 4.63.0 | 0 / 0 | |
| 4.62.1 | 0 / 0 | |
| 4.62.0 | 0 / 0 | |
| 4.61.0 | 0 / 0 | |
| 4.60.1 | 0 / 0 | |
| 4.60.0 | 0 / 0 | |
| 4.59.10 | 0 / 0 | |
| 4.59.9 | 0 / 0 | |
| 4.59.8 | 0 / 0 | |
| 4.59.7 | 0 / 0 | |
| 4.59.6 | 0 / 0 | |
| 4.59.5 | 0 / 0 | |
| 4.59.4 | 0 / 0 | |
| 4.59.3 | 0 / 0 | |
| 4.59.2 | 0 / 0 | |
| 4.59.1 | 0 / 0 | |
| 4.59.0 | 0 / 0 | |
| 4.58.2 | 0 / 0 | |
| 4.58.1 | 0 / 0 | |
| 4.58.0 | 0 / 0 | |
| 4.57.4 | 0 / 0 | |
| 4.57.3 | 0 / 0 | |
| 4.57.2 | 0 / 0 | |
| 4.57.1 | 0 / 0 | |
| 4.57.0 | 0 / 0 |
v4.67.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.67.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.66.4
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.66.3
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.66.2
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.66.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.66.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.65.5
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.65.4
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.65.3
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.65.2
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.65.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.65.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.64.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.64.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.63.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.62.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.62.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.61.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.60.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.60.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.10
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.9
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.8
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.7
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.6
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.5
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.4
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.3
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.2
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.59.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.58.2
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.58.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.58.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.57.4
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.57.3
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.57.2
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.57.1
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.57.0
2 findingsPackage name '@sasjs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.