@stacksjs/registry
Pantry package registry backend - S3 storage with DynamoDB metadata
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-dropped | AI (source-diff): Package is intentionally a ~390B typed re-export of @stacksjs/types; large src/chart deps were removed. Size drop is by design. | ai | |
| source-diff | net-exec-file-transition:dist/index.js | AI (source-diff): Standard fs/crypto/stream usage in a storage backend bundle, no dropper behavior observed. | ai | |
| source-diff | obfuscated-file-transition:dist/index.js | AI (source-diff): Bun-bundled output with readable identifiers, not true obfuscation. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): CI/CD provenance-backed release cadence, no malicious indicators. | ai | |
| provenance | publisher-changed | AI (provenance): Manual-to-CI/CD migration with SLSA attestation, not a compromise indicator. | ai | |
| dependencies | unvetted-dep:@ts-charts/scale | AI (dependencies): Sibling ecosystem chart lib, low-risk config-only usage. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are stacksjs/ts-charts ecosystem packages, not unrelated third parties. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase driven by bundling new legitimate deps, not injected payload. | ai | |
| phantom-deps | phantom-dep:@ts-charts/array | AI (phantom-deps): Referenced in config files per finding; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ts-charts/path | AI (phantom-deps): Referenced in config files per finding; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ts-charts/shape | AI (phantom-deps): Referenced in config files per finding; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ts-charts/scale | AI (phantom-deps): Referenced in config files per finding; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ts-charts/format | AI (phantom-deps): Referenced in config files per finding; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@stacksjs/stx | AI (phantom-deps): Same org scope; declared for config/peer use, not a malicious phantom dep pattern. | ai |
Versions (showing 51 of 99)
| Version | Deps | Published |
|---|---|---|
| 0.70.190 | 1 / 1 | |
| 0.70.163 | 1 / 1 | |
| 0.70.162 | 1 / 1 | |
| 0.70.130 | 0 / 1 | |
| 0.70.123 | 0 / 1 | |
| 0.70.117 | 0 / 1 | |
| 0.70.114 | 0 / 1 | |
| 0.70.111 | 0 / 1 | |
| 0.70.98 | 0 / 1 | |
| 0.70.81 | 0 / 1 | |
| 0.70.80 | 0 / 1 | |
| 0.70.79 | 0 / 1 | |
| 0.70.78 | 0 / 1 | |
| 0.70.77 | 0 / 1 | |
| 0.70.76 | 0 / 1 | |
| 0.70.75 | 0 / 1 | |
| 0.70.74 | 0 / 1 | |
| 0.70.73 | 0 / 1 | |
| 0.70.72 | 0 / 1 | |
| 0.70.71 | 0 / 1 | |
| 0.70.70 | 0 / 1 | |
| 0.70.69 | 0 / 1 | |
| 0.70.68 | 0 / 1 | |
| 0.70.67 | 0 / 1 | |
| 0.70.66 | 0 / 1 | |
| 0.70.65 | 0 / 1 | |
| 0.70.64 | 0 / 1 | |
| 0.70.63 | 0 / 1 | |
| 0.70.62 | 0 / 1 | |
| 0.70.61 | 0 / 1 | |
| 0.70.60 | 0 / 1 | |
| 0.70.59 | 0 / 1 | |
| 0.70.58 | 0 / 1 | |
| 0.70.57 | 0 / 1 | |
| 0.70.56 | 0 / 1 | |
| 0.70.55 | 0 / 1 | |
| 0.70.54 | 0 / 1 | |
| 0.70.53 | 0 / 1 | |
| 0.70.45 | 0 / 1 | |
| 0.70.44 | 0 / 1 | |
| 0.70.43 | 0 / 1 | |
| 0.70.42 | 0 / 1 | |
| 0.70.41 | 0 / 1 | |
| 0.70.40 | 0 / 1 | |
| 0.70.39 | 0 / 1 | |
| 0.70.38 | 0 / 1 | |
| 0.70.37 | 0 / 1 | |
| 0.70.36 | 0 / 1 | |
| 0.70.35 | 0 / 1 | |
| 0.70.34 | 0 / 1 | |
| 0.70.33 | 0 / 1 |
v0.70.190
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (chrisbreuer) than the most recent previously approved version (GitHub Actions) on 2026-07-27, but chrisbreuer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.70.163
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (chrisbreuer) than the most recent previously approved version (GitHub Actions) on 2026-07-23, but chrisbreuer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.70.162
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (chrisbreuer) than the most recent previously approved version (GitHub Actions) on unknown date, but chrisbreuer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.70.130
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v0.70.123
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (chrisbreuer) than the most recent previously approved version (GitHub Actions) on 2026-07-19, but chrisbreuer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.70.117
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (chrisbreuer) than the most recent previously approved version (GitHub Actions) on 2026-07-19, but chrisbreuer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.70.114
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v0.70.111
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v0.70.98
2 findings[Reject — re-review on republish] (prior reject: AI (provenance): Provenance regression combined with near-total source size collapse indicates compromised or broken publish.) This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (chrisbreuer) than the most recent previously approved version (GitHub Actions) on 2026-07-17, but chrisbreuer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.70.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.80
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.79
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.78
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.77
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.76
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.74
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (chrisbreuer) on 2026-07-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.70.73
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.72
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.71
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.70
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.69
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.68
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.67
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.66
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.65
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.64
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.63
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.62
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.61
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.60
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.59
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.58
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.57
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.56
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.55
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.54
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.53
2 findingsThis version was published by a different npm account than previous versions on 2026-07-10. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.