@tak-ps/node-cot
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Dep swap from archiver to @archiver/archiver is a scoped refactor, not an injection; SLSA provenance and CI publisher reduce risk. | ai | |
| phantom-deps | phantom-dep:geomagnetism | AI (phantom-deps): Domain-appropriate geospatial dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:mil-std-2525 | AI (phantom-deps): Military symbology dep appropriate for TAK message library; heuristic false positive. | ai | |
| phantom-deps | phantom-dep:milsymbol | AI (phantom-deps): TypeScript project; milsymbol is a domain-appropriate optional dep, not directly imported in all code paths. | ai | |
| phantom-deps | phantom-dep:@types/geojson | AI (phantom-deps): Type-only package loaded by convention in TypeScript projects; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/archiver | AI (phantom-deps): Type-only package loaded by convention in TypeScript projects; stable false positive. | ai | |
| phantom-deps | phantom-dep:milstandard-e | AI (phantom-deps): Military symbology dep appropriate for TAK message library; heuristic false positive. | ai |
Versions (showing 51 of 88)
| Version | Deps | Published |
|---|---|---|
| 14.48.0 | 21 / 8 | |
| 14.47.0 | 21 / 8 | |
| 14.46.0 | 21 / 8 | |
| 14.45.1 | 21 / 8 | |
| 14.45.0 | 21 / 8 | |
| 14.44.3 | 22 / 8 | |
| 14.44.2 | 22 / 8 | |
| 14.44.1 | 22 / 8 | |
| 14.44.0 | 22 / 8 | |
| 14.43.2 | 22 / 8 | |
| 14.43.1 | 22 / 8 | |
| 14.42.1 | 22 / 8 | |
| 14.42.0 | 23 / 8 | |
| 14.41.0 | 23 / 8 | |
| 14.40.1 | 23 / 8 | |
| 14.40.0 | 23 / 8 | |
| 14.39.0 | 23 / 8 | |
| 14.38.0 | 23 / 8 | |
| 14.37.2 | 24 / 8 | |
| 14.37.1 | 24 / 8 | |
| 14.37.0 | 24 / 8 | |
| 14.36.0 | 24 / 8 | |
| 14.35.1 | 24 / 8 | |
| 14.34.0 | 24 / 8 | |
| 14.33.0 | 24 / 10 | |
| 14.32.0 | 24 / 10 | |
| 14.31.0 | 24 / 10 | |
| 14.30.1 | 24 / 10 | |
| 14.30.0 | 24 / 10 | |
| 14.29.0 | 24 / 10 | |
| 14.28.1 | 24 / 10 | |
| 14.28.0 | 24 / 10 | |
| 14.27.0 | 24 / 10 | |
| 14.26.0 | 24 / 10 | |
| 14.25.0 | 24 / 10 | |
| 14.24.3 | 24 / 10 | |
| 14.24.2 | 24 / 10 | |
| 14.24.1 | 24 / 10 | |
| 14.24.0 | 24 / 10 | |
| 14.23.2 | 24 / 9 | |
| 14.23.1 | 24 / 9 | |
| 14.23.0 | 24 / 9 | |
| 14.22.1 | 24 / 9 | |
| 14.20.1 | 24 / 9 | |
| 14.20.0 | 24 / 9 | |
| 14.19.0 | 24 / 9 | |
| 14.18.4 | 24 / 9 | |
| 14.18.3 | 24 / 9 | |
| 14.17.0 | 24 / 9 | |
| 14.16.0 | 24 / 9 | |
| 14.15.0 | 23 / 9 |
v14.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.45.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.44.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.44.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.44.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.43.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.43.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.37.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.37.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.36.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.35.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.31.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.28.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.24.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.23.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.22.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.19.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.18.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.18.3
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ingalls) on 2026-01-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v14.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.