@signalk/server-admin-ui
Signal K server admin webapp
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:public/assets/bootstrap-CkVvyXgI.js | AI (source-diff): Bundled frontend JS; network/eval patterns are from bundler runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-CkVvyXgI.js | AI (source-diff): Minified Vite build output, not true obfuscation; contains readable React library code. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-Dl8NOv2y.js | AI (source-diff): Vite bundle output, bundler banner present, standard React/vendor code. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-Dl8NOv2y.js | AI (source-diff): Vite-bundled app entry, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-6CM60CZx.js | AI (source-diff): Vite bundle output for React app, not obfuscation. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-6CM60CZx.js | AI (source-diff): Vite bundle output, module federation loading is expected. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-bNZv2cMS.js | AI (source-diff): Bundled federation runtime code, no malicious network/exec behavior evident. | ai | |
| source-diff | net-exec-file:public/assets/index.cjs-qNTcCtpj.js | AI (source-diff): Federation manifest loader code, no malicious destination found. | ai | |
| source-diff | obfuscated-file:public/assets/index.cjs-qNTcCtpj.js | AI (source-diff): Module-federation runtime bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:public/assets/index-C0euSWDO.js | AI (source-diff): Minified React/scheduler library code, standard bundler output. | ai | |
| source-diff | obfuscated-file:public/assets/index-BEQk0SN_.js | AI (source-diff): Minified React library code, standard bundler output. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-bNZv2cMS.js | AI (source-diff): Vite/module-federation bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:public/assets/index-CHqwNyl4.js | AI (source-diff): MF runtime uses new Function()/fetch internally; not exfil. | ai | |
| source-diff | obfuscated-file:public/assets/index-C5SbDtSm.js | AI (source-diff): Bundled React/vite output. | ai | |
| source-diff | obfuscated-file:public/assets/index-BO-OvZjH.js | AI (source-diff): Bundled React/vite output. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-D-Os68-G.js | AI (source-diff): Module Federation runtime loader pattern, not a dropper. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-D-Os68-G.js | AI (source-diff): Vite/Module-Federation bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:public/assets/index-CHqwNyl4.js | AI (source-diff): Module Federation runtime bundle, not obfuscation. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-CZMNYFm2.js | AI (source-diff): Bundled React/websocket client code, not a dropper. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-CZMNYFm2.js | AI (source-diff): Vite/webpack bundled frontend asset, not true obfuscation. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-DhdGWh46.js | AI (source-diff): Bundled frontend code with normal fetch/websocket usage, not a dropper. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-DhdGWh46.js | AI (source-diff): Vite bundle output for React UI, not true obfuscation. | ai | |
| source-diff | obfuscated-file:public/assets/index-DGNZrxCr.js | AI (source-diff): Rollup-bundled React/scheduler code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-OBqvctZP.js | AI (source-diff): Module-federation runtime bundle, minified not obfuscated. | ai | |
| source-diff | net-exec-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-OBqvctZP.js | AI (source-diff): Bundled federation runtime; no exfil/dropper behavior found. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-CX1Fo5Ij.js | AI (source-diff): Vite-bundled React app entry, minified build output. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-CX1Fo5Ij.js | AI (source-diff): Vite bundle; network/eval patterns are bundler runtime, not malicious. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap--2xek4Qw.js | AI (source-diff): Vite bundle importing MF runtime, benign. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap--2xek4Qw.js | AI (source-diff): Vite-bundled entry file, minified not obfuscated. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-Sl5eJoZ5.js | AI (source-diff): Bundled frontend JS; network+eval patterns are React/bundler internals, not a dropper. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-Sl5eJoZ5.js | AI (source-diff): Vite/rollup bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-NX_x-zUe.js | AI (source-diff): Bundled React/UI code false-positives on network+eval heuristics; no concrete malicious behavior. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-NX_x-zUe.js | AI (source-diff): Vite/rollup bundled webapp asset, matches declared build tooling, not true obfuscation. | ai | |
| source-diff | obfuscated-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js | AI (source-diff): Module Federation runtime bundle, minified not obfuscated malware. | ai | |
| source-diff | net-exec-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js | AI (source-diff): Federation runtime loader; network+eval is its documented remote-module-loading function. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): Inside Module Federation runtime's remote-loading logic, not injected code. | ai | |
| source-diff | obfuscated-file:public/assets/index-5hkOWmYo.js | AI (source-diff): React scheduler minified bundle. | ai | |
| source-diff | obfuscated-file:public/assets/index-03avmwGu.js | AI (source-diff): React production minified bundle. | ai | |
| source-diff | net-exec-file:public/assets/bootstrap-Ca_bYwBS.js | AI (source-diff): Bundled app entry, false positive from minified size. | ai | |
| source-diff | obfuscated-file:public/assets/bootstrap-Ca_bYwBS.js | AI (source-diff): Vite bundle output for React app entry, minified not malicious. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Long-running project maintainer churn, publisher is trusted known maintainer. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established 8yr+ SignalK ecosystem package, metadata sparsity is not spam. | ai | |
| source-diff | obfuscated-file:public/323.js | AI (source-diff): Webpack bundle of app's own login/websocket code, not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:zustand | AI (phantom-deps): zustand is a declared runtime dependency; used in built output, not directly imported in source files scanned. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in bundled module federation runtime (remoteEntry.js); standard vite/webpack federation pattern, not malicious. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 2.30.0 | 1 / 60 | |
| 2.28.2 | 1 / 61 | |
| 2.28.1 | 1 / 61 | |
| 2.28.0 | 1 / 61 | |
| 2.27.0 | 1 / 55 | |
| 2.26.0 | 1 / 55 | |
| 2.25.0 | 1 / 54 | |
| 2.24.2 | 1 / 53 | |
| 2.24.1 | 1 / 53 | |
| 2.24.0 | 1 / 53 | |
| 2.23.2 | 0 / 43 | |
| 2.23.1 | 0 / 43 | |
| 2.23.0 | 0 / 43 | |
| 2.21.0 | 0 / 42 | |
| 2.20.3 | 0 / 42 | |
| 2.20.2 | 0 / 42 | |
| 2.20.1 | 0 / 42 | |
| 2.20.0 | 0 / 42 | |
| 2.19.5 | 0 / 47 | |
| 2.19.4 | 0 / 48 | |
| 2.19.3 | 0 / 48 | |
| 2.19.2 | 0 / 48 | |
| 2.19.1 | 0 / 48 | |
| 2.19.0 | 0 / 48 | |
| 2.18.0 | 0 / 44 |
v2.30.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.28.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.2
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-03-12, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.23.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-03-08, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.23.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-03-03, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.21.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-02-09, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.20.3
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-02-09, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.20.2
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-27, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.20.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-19, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.20.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-18, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.19.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-06, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.19.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-01, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.19.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2025-12-27, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.19.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2025-12-12, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.19.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.