@semantic-release/last-release-npm
Determine the version of the last release via the npm registry
10
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
gr2mchristophwitzkoboennemannsemantic-release-bot
Keywords
npmregistrysemantic-releaseversion
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): The transition from semantic-release to semantic-release-bot occurred in Dec 2016 and reflects the org's standard practice of using an automation bot. semantic-release-bot has 976 approved packages and is the official publisher for the @semantic-release scope. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): semantic-release-bot is the official automation account for the semantic-release org; its addition is a legitimate and long-standing organizational transition, not a compromise. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of the human semantic-release account in favor of the bot account is a documented org practice, not a hijack signal for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change from gr2m to semantic-release-bot is the documented, well-known transition to the official semantic-release automation account. Occurred in 2017; bot has 970 approved packages and 0 rejections. | ai |