@strapi/helper-plugin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:react-select | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:react-helmet | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:formik | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:react-intl | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:react-query | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| source-diff | obfuscated-file-transition:dist/content-manager/utils/contentManagementUtilRemoveFieldsFromData.d.ts | AI (source-diff): Long-line .d.ts is complex TS generic type, not obfuscation. | ai | |
| source-diff | obfuscated-file-transition:dist/content-manager/utils/formatContentTypeData.d.ts | AI (source-diff): Long-line .d.ts is complex TS generic type, not obfuscation. | ai | |
| phantom-deps | phantom-dep:classnames | AI (phantom-deps): Same as above. | ai | |
| phantom-deps | phantom-dep:immutable | AI (phantom-deps): Same as above. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established 74k/wk scoped Strapi package; README/keyword heuristics are FPs here. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:invariant | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Standard React peer dep, used in unscanned source. | ai | |
| phantom-deps | phantom-dep:match-sorter | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:react-router | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:mini-css-extract-plugin | AI (phantom-deps): Webpack build tool dep, not expected in source imports. | ai | |
| phantom-deps | phantom-dep:@fortawesome/fontawesome-free | AI (phantom-deps): CSS/asset-only fontawesome package, not imported as JS. | ai | |
| phantom-deps | phantom-dep:@fortawesome/react-fontawesome | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:babel-plugin-styled-components | AI (phantom-deps): Babel plugin, referenced in babel config not source imports. | ai | |
| phantom-deps | phantom-dep:@fortawesome/fontawesome-svg-core | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-solid-svg-icons | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-brands-svg-icons | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): Common prop-types false positive in bundled React libs. | ai | |
| phantom-deps | phantom-dep:immer | AI (phantom-deps): Bundled build output; immer likely used internally, no scannable import. | ai |
Versions (showing 51 of 156)
| Version | Deps | Published |
|---|---|---|
| 4.26.1 | 10 / 27 | |
| 4.25.24 | 10 / 27 | |
| 4.25.23 | 10 / 27 | |
| 4.25.22 | 10 / 27 | |
| 4.25.21 | 10 / 27 | |
| 4.25.20 | 10 / 27 | |
| 4.25.19 | 10 / 27 | |
| 4.25.18 | 10 / 27 | |
| 4.25.17 | 10 / 27 | |
| 4.25.16 | 10 / 27 | |
| 4.25.15 | 10 / 27 | |
| 4.25.14 | 10 / 27 | |
| 4.25.13 | 10 / 27 | |
| 4.25.12 | 10 / 27 | |
| 4.25.11 | 10 / 27 | |
| 4.25.10 | 10 / 27 | |
| 4.25.9 | 10 / 27 | |
| 4.25.8 | 10 / 27 | |
| 4.25.7 | 10 / 27 | |
| 4.25.6 | 10 / 27 | |
| 4.25.5 | 10 / 27 | |
| 4.25.4 | 10 / 27 | |
| 4.25.3 | 10 / 27 | |
| 4.25.2 | 10 / 27 | |
| 4.25.1 | 10 / 27 | |
| 4.25.0 | 10 / 27 | |
| 4.24.5 | 10 / 27 | |
| 4.24.4 | 10 / 27 | |
| 4.24.3 | 10 / 27 | |
| 4.24.2 | 10 / 27 | |
| 4.24.1 | 10 / 27 | |
| 4.24.0 | 10 / 27 | |
| 4.23.2 | 10 / 27 | |
| 4.23.1 | 10 / 27 | |
| 4.23.0 | 10 / 26 | |
| 4.22.1 | 10 / 26 | |
| 4.21.1 | 10 / 26 | |
| 4.20.5 | 10 / 26 | |
| 4.20.4 | 10 / 26 | |
| 4.20.3 | 10 / 26 | |
| 4.20.2 | 10 / 26 | |
| 4.20.0 | 10 / 26 | |
| 4.19.1 | 10 / 26 | |
| 4.19.0 | 10 / 26 | |
| 4.18.0 | 10 / 26 | |
| 4.17.1 | 10 / 26 | |
| 4.17.0 | 10 / 26 | |
| 4.16.2 | 10 / 31 | |
| 4.16.1 | 10 / 31 | |
| 4.16.0 | 10 / 31 | |
| 4.15.5 | 10 / 31 |
v4.26.1
2 findingsThis version was published by a different npm account (bassel17) than the most recent previously approved version (baronvoninternet) on 2026-01-08. It has since remained available on npm for 194 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.22
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (marc-roig-strapi) on 2025-03-19, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.21
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (baronvoninternet) on 2025-03-12, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.20
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (baronvoninternet) on 2025-01-22, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (baronvoninternet) than the most recent previously approved version (convly) on 2025-01-09, but baronvoninternet is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (remidej) on 2024-11-21, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.16
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (baronvoninternet) than the most recent previously approved version (remidej) on 2024-11-13, but baronvoninternet is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (remidej) on 2024-10-23, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (convly) on 2024-09-11, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-09-04, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-08-14, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2024-08-07, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (marc-roig-strapi) on 2024-07-31, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (remidej) on 2024-07-24, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (remidej) on 2024-07-17, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (convly) on 2024-07-10, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-07-03, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (markkaylor) on 2024-06-19, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (markkaylor) on 2024-06-12, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-06-05, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.24.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2024-05-22, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.24.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (alexandrebodin) on 2024-05-02, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-04-24, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.23.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.23.1
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-04-10, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.22.1
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2024-04-05, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.21.1
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.20.5
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-03-13, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.20.4
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.20.3
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.20.2
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-02-21, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.20.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-02-07, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.19.1
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-01-31, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.19.0
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.18.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-01-12, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.17.1
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2024-01-16, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.17.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-01-10, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.16.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (markkaylor) on 2023-12-21, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.16.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (alexandrebodin) on 2023-12-20, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (alexandrebodin) on 2023-11-29, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.