@strapi/helper-plugin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:react-select | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:react-helmet | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:formik | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:react-intl | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:react-query | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Common Strapi runtime dep, false positive from bundled build. | ai | |
| source-diff | obfuscated-file-transition:dist/content-manager/utils/contentManagementUtilRemoveFieldsFromData.d.ts | AI (source-diff): Long-line .d.ts is complex TS generic type, not obfuscation. | ai | |
| source-diff | obfuscated-file-transition:dist/content-manager/utils/formatContentTypeData.d.ts | AI (source-diff): Long-line .d.ts is complex TS generic type, not obfuscation. | ai | |
| phantom-deps | phantom-dep:classnames | AI (phantom-deps): Same as above. | ai | |
| phantom-deps | phantom-dep:immutable | AI (phantom-deps): Same as above. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established 74k/wk scoped Strapi package; README/keyword heuristics are FPs here. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:invariant | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Standard React peer dep, used in unscanned source. | ai | |
| phantom-deps | phantom-dep:match-sorter | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:react-router | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:mini-css-extract-plugin | AI (phantom-deps): Webpack build tool dep, not expected in source imports. | ai | |
| phantom-deps | phantom-dep:@fortawesome/fontawesome-free | AI (phantom-deps): CSS/asset-only fontawesome package, not imported as JS. | ai | |
| phantom-deps | phantom-dep:@fortawesome/react-fontawesome | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:babel-plugin-styled-components | AI (phantom-deps): Babel plugin, referenced in babel config not source imports. | ai | |
| phantom-deps | phantom-dep:@fortawesome/fontawesome-svg-core | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-solid-svg-icons | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-brands-svg-icons | AI (phantom-deps): Used in unscanned source, only build output scanned. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): Common prop-types false positive in bundled React libs. | ai | |
| phantom-deps | phantom-dep:immer | AI (phantom-deps): Bundled build output; immer likely used internally, no scannable import. | ai |
Versions (showing 100 of 156)
| Version | Deps | Published |
|---|---|---|
| 4.26.1 | 10 / 27 | |
| 4.25.24 | 10 / 27 | |
| 4.25.23 | 10 / 27 | |
| 4.25.22 | 10 / 27 | |
| 4.25.21 | 10 / 27 | |
| 4.25.20 | 10 / 27 | |
| 4.25.19 | 10 / 27 | |
| 4.25.18 | 10 / 27 | |
| 4.25.17 | 10 / 27 | |
| 4.25.16 | 10 / 27 | |
| 4.25.15 | 10 / 27 | |
| 4.25.14 | 10 / 27 | |
| 4.25.13 | 10 / 27 | |
| 4.25.12 | 10 / 27 | |
| 4.25.11 | 10 / 27 | |
| 4.25.10 | 10 / 27 | |
| 4.25.9 | 10 / 27 | |
| 4.25.8 | 10 / 27 | |
| 4.25.7 | 10 / 27 | |
| 4.25.6 | 10 / 27 | |
| 4.25.5 | 10 / 27 | |
| 4.25.4 | 10 / 27 | |
| 4.25.3 | 10 / 27 | |
| 4.25.2 | 10 / 27 | |
| 4.25.1 | 10 / 27 | |
| 4.25.0 | 10 / 27 | |
| 4.24.5 | 10 / 27 | |
| 4.24.4 | 10 / 27 | |
| 4.24.3 | 10 / 27 | |
| 4.24.2 | 10 / 27 | |
| 4.24.1 | 10 / 27 | |
| 4.24.0 | 10 / 27 | |
| 4.23.2 | 10 / 27 | |
| 4.23.1 | 10 / 27 | |
| 4.23.0 | 10 / 26 | |
| 4.22.1 | 10 / 26 | |
| 4.21.1 | 10 / 26 | |
| 4.20.5 | 10 / 26 | |
| 4.20.4 | 10 / 26 | |
| 4.20.3 | 10 / 26 | |
| 4.20.2 | 10 / 26 | |
| 4.20.0 | 10 / 26 | |
| 4.19.1 | 10 / 26 | |
| 4.19.0 | 10 / 26 | |
| 4.18.0 | 10 / 26 | |
| 4.17.1 | 10 / 26 | |
| 4.17.0 | 10 / 26 | |
| 4.16.2 | 10 / 31 | |
| 4.16.1 | 10 / 31 | |
| 4.16.0 | 10 / 31 | |
| 4.15.5 | 10 / 31 | |
| 4.15.4 | 10 / 31 | |
| 4.15.3 | 10 / 31 | |
| 4.15.2 | 10 / 31 | |
| 4.15.1 | 10 / 31 | |
| 4.15.0 | 10 / 31 | |
| 4.14.6 | 10 / 31 | |
| 4.14.5 | 10 / 31 | |
| 4.14.3 | 11 / 35 | |
| 4.14.2 | 11 / 35 | |
| 4.14.1 | 11 / 35 | |
| 4.14.0 | 11 / 35 | |
| 4.13.7 | 11 / 35 | |
| 4.13.6 | 11 / 32 | |
| 4.13.5 | 11 / 31 | |
| 4.13.4 | 11 / 31 | |
| 4.13.3 | 11 / 31 | |
| 4.13.2 | 11 / 31 | |
| 4.13.1 | 11 / 31 | |
| 4.13.0 | 11 / 31 | |
| 4.12.7 | 11 / 31 | |
| 4.12.6 | 11 / 31 | |
| 4.12.5 | 11 / 31 | |
| 4.12.4 | 11 / 27 | |
| 4.12.3 | 11 / 27 | |
| 4.12.2 | 11 / 27 | |
| 4.12.1 | 11 / 22 | |
| 4.12.0 | 11 / 22 | |
| 4.11.7 | 11 / 22 | |
| 4.11.6 | 11 / 22 | |
| 4.11.5 | 11 / 22 | |
| 4.11.4 | 11 / 23 | |
| 4.11.3 | 10 / 22 | |
| 4.11.2 | 10 / 22 | |
| 4.11.1 | 10 / 22 | |
| 4.11.0 | 10 / 22 | |
| 4.10.8 | 10 / 23 | |
| 4.10.7 | 10 / 23 | |
| 4.10.6 | 10 / 23 | |
| 4.10.5 | 10 / 23 | |
| 4.10.4 | 10 / 23 | |
| 4.10.3 | 10 / 23 | |
| 4.10.2 | 10 / 23 | |
| 4.10.1 | 10 / 23 | |
| 4.10.0 | 10 / 23 | |
| 4.9.2 | 10 / 23 | |
| 4.9.1 | 10 / 24 | |
| 4.9.0 | 10 / 24 | |
| 4.8.2 | 10 / 24 | |
| 4.8.1 | 10 / 24 |
v4.26.1
2 findingsThis version was published by a different npm account (bassel17) than the most recent previously approved version (baronvoninternet) on 2026-01-08. It has since remained available on npm for 194 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.22
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (marc-roig-strapi) on 2025-03-19, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.21
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (baronvoninternet) on 2025-03-12, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.20
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (baronvoninternet) on 2025-01-22, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (baronvoninternet) than the most recent previously approved version (convly) on 2025-01-09, but baronvoninternet is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (remidej) on 2024-11-21, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.16
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (baronvoninternet) than the most recent previously approved version (remidej) on 2024-11-13, but baronvoninternet is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (remidej) on 2024-10-23, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (convly) on 2024-09-11, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-09-04, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-08-14, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2024-08-07, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (marc-roig-strapi) on 2024-07-31, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (remidej) on 2024-07-24, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (remidej) on 2024-07-17, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (remidej) than the most recent previously approved version (convly) on 2024-07-10, but remidej is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-07-03, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (markkaylor) on 2024-06-19, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.25.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (markkaylor) on 2024-06-12, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-06-05, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.24.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2024-05-22, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.24.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (alexandrebodin) on 2024-05-02, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.24.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-04-24, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.23.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.23.1
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2024-04-10, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.22.1
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2024-04-05, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.21.1
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.20.5
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-03-13, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.20.4
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.20.3
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.20.2
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-02-21, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.20.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-02-07, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.19.1
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-01-31, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.19.0
3 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.18.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-01-12, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.17.1
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2024-01-16, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.17.0
4 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (convly) on 2024-01-10, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.16.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (markkaylor) on 2023-12-21, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.16.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (alexandrebodin) on 2023-12-20, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (alexandrebodin) on 2023-11-29, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (markkaylor) on 2023-11-11, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (markkaylor) on 2023-11-11, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (alexandrebodin) on 2023-11-08, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (markkaylor) on 2023-11-02, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.15.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (markkaylor) on 2023-10-25, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.14.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.14.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (markkaylor) than the most recent previously approved version (marc-roig-strapi) on 2023-10-18, but markkaylor is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.14.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2023-10-04, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.14.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (alexandrebodin) on 2023-10-02, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.14.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (alexandrebodin) on 2023-09-28, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.13.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.13.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.13.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2023-09-12, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.13.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2023-09-11, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.13.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (alexandrebodin) on 2023-09-06, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.13.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (alexandrebodin) on 2023-09-04, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.13.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.13.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (alexandrebodin) on 2023-08-30, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.12.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (marc-roig-strapi) on 2023-08-25, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.12.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (marc-roig-strapi) on 2023-08-23, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.12.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2023-08-16, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.12.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.12.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.12.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.12.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2023-07-27, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2023-07-19, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2023-07-19, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2023-07-05, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2023-06-28, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (alexandrebodin) on 2023-06-21, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (alexandrebodin) on 2023-06-12, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.11.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2023-06-07, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.10.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (marc-roig-strapi) on 2023-05-10, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.10.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (marc-roig-strapi) than the most recent previously approved version (convly) on 2023-05-10, but marc-roig-strapi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.10.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (alexandrebodin) on 2023-05-03, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2023-04-26, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.9.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.8.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (convly) than the most recent previously approved version (alexandrebodin) on 2023-03-16, but convly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.8.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexandrebodin) than the most recent previously approved version (convly) on 2023-03-15, but alexandrebodin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.