@teambit/ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/746.5693958d.js | AI (source-diff): Webpack-bundled UI asset, minified not obfuscated; stable pattern for this package's artifacts. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo with 3460 versions publishes frequently in short succession; expected cadence. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/856.35cd36db.js | AI (source-diff): Same bundled artifact duplicated across workspace/scope builds. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/856.35cd36db.js | AI (source-diff): Same bundled artifact duplicated across workspace/scope builds. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/746.5693958d.js | AI (source-diff): Bundled graphlib/layout code; network+eval pattern is generic bundler output, no malicious target. | ai | |
| dependencies | unvetted-dep:@teambit/design.themes.theme-toggler | AI (dependencies): First-party @teambit monorepo dependency. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in webpack bundle runtime loader, standard bundler pattern not obfuscation. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): First-party @teambit monorepo dependency. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package; missing description is cosmetic, not a malware signal. | ai | |
| provenance | no-provenance | AI (provenance): Only ~12% of npm packages have provenance; not a disqualifier for established packages. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/505.91cef6dd.js | AI (source-diff): Webpack-bundled minified UI asset, not obfuscation; recurring pattern for this package's build artifacts. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.7bb8cc98.js | AI (source-diff): Bundled frontend code; benign for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.7bb8cc98.js | AI (source-diff): Webpack-bundled minified UI asset, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/505.91cef6dd.js | AI (source-diff): Bundled frontend code; net+eval patterns are standard webpack runtime, not a dropper. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.9f0f0617.js | AI (source-diff): Same bundled asset pattern, mirrored workspace build. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.9f0f0617.js | AI (source-diff): Same bundled asset pattern, mirrored workspace build. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/505.bde6abb1.js | AI (source-diff): Bundled UI code; sample shows layout library, no exfil behavior. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/505.bde6abb1.js | AI (source-diff): Webpack-bundled UI asset (dagre/graphlib), minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.c3c59170.js | AI (source-diff): Same bundled webpack chunk pattern as sibling artifact. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/505.c64c9393.js | AI (source-diff): Webpack-bundled UI static asset, not obfuscation; large minified chunk is expected build output. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/505.c64c9393.js | AI (source-diff): Bundled webpack chunk (graphlib/layout libs), no evidence of dropper/loader behavior. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.c3c59170.js | AI (source-diff): Same bundled webpack chunk pattern as sibling artifact. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/814.868fba5b.js | AI (source-diff): Bundled webpack chunk false-positive; no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/814.868fba5b.js | AI (source-diff): Webpack-bundled UI build artifact; sample shows legitimate graphlib/layout code, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/263.3f8bce79.js | AI (source-diff): Bundled webpack chunk false-positive; no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/263.3f8bce79.js | AI (source-diff): Webpack-bundled UI build artifact; sample shows legitimate graphlib/layout code, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.45ddbd22.js | AI (source-diff): Browser bundle with network calls is normal for a UI framework package; not a dropper pattern. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/747.65bc0367.js | AI (source-diff): Browser bundle with network calls is normal for a UI framework package; not a dropper pattern. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/747.65bc0367.js | AI (source-diff): Standard webpack-minified UI bundle artifact; expected for @teambit/ui shipping pre-built browser assets. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.45ddbd22.js | AI (source-diff): Standard webpack-minified UI bundle artifact; expected for @teambit/ui shipping pre-built browser assets. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/196.6ebaafb5.js | AI (source-diff): Browser UI bundle; network calls and dynamic module loading are normal webpack chunk patterns, not dropper malware. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/248.7a08bbf9.js | AI (source-diff): Browser UI bundle; network calls and dynamic module loading are normal webpack chunk patterns, not dropper malware. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/248.7a08bbf9.js | AI (source-diff): Webpack-bundled UI artifact; minified JS is expected for @teambit/ui's pre-built browser bundles. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/196.6ebaafb5.js | AI (source-diff): Webpack-bundled UI artifact; minified JS is expected for @teambit/ui's pre-built browser bundles. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/515.10d69c43.js | AI (source-diff): Browser UI bundle with fetch/XHR and dynamic module loading is expected for this package's UI artifacts. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/515.10d69c43.js | AI (source-diff): Standard webpack minified browser bundle artifact; pattern is stable across all versions of this package. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/913.6f89dc84.js | AI (source-diff): Standard webpack minified browser bundle artifact; pattern is stable across all versions of this package. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/913.6f89dc84.js | AI (source-diff): Browser UI bundle with fetch/XHR and dynamic module loading is expected for this package's UI artifacts. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/747.bfe65073.js | AI (source-diff): Same webpack module loader pattern; not malicious. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.12051623.js | AI (source-diff): Webpack chunk containing graphlib/layout code; standard minified build artifact for Bit's UI bundle. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.12051623.js | AI (source-diff): Network calls and dynamic requires are webpack module loader patterns in a browser UI bundle, not dropper malware. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/747.bfe65073.js | AI (source-diff): Identical webpack chunk pattern as workspace bundle; standard minified build artifact. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/754.9ab2c3f1.js | AI (source-diff): Webpack bundle for browser UI; network calls and dynamic module loading are expected in this context. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/754.9ab2c3f1.js | AI (source-diff): Standard webpack minified UI bundle for @teambit/ui; not obfuscation, consistent with prior releases. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/652.16d96174.js | AI (source-diff): Webpack bundle for browser UI; network calls and dynamic module loading are expected in this context. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/652.16d96174.js | AI (source-diff): Standard webpack minified UI bundle for @teambit/ui; not obfuscation, consistent with prior releases. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/232.013ebf4f.js | AI (source-diff): Webpack UI bundle chunk; minified graphlib/dagre layout code, not malware. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/594.04fdc8e6.js | AI (source-diff): Webpack module system pattern; net-exec signal is webpack require(), not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/594.04fdc8e6.js | AI (source-diff): Webpack UI bundle chunk; same graphlib content as workspace bundle, not malware. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/232.013ebf4f.js | AI (source-diff): Webpack module system pattern; network+exec signal is webpack require(), not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/ssr/57e0cc5db6a609b0.cjs | AI (source-diff): SSR bundle artifact; minified React/TypeScript output, not obfuscated malware. | ai | |
| dependencies | unvetted-dep:@teambit/api-reference.hooks.use-api-renderers | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/rspack.modules.generate-asset-manifest | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/harmony.modules.harmony-root-generator | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/base-react.themes.theme-switcher | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/design.themes.light-theme | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/design.themes.dark-theme | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/design.themes.base-theme | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.crypto.sha1 | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/react.rendering.ssr | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. | ai | |
| dependencies | unvetted-dep:http-proxy | AI (dependencies): Well-known proxy library; stable dependency in this package's build toolchain. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/139.64a0671d.js | AI (source-diff): Webpack bundle for browser UI; network+dynamic-require is normal for bundled frontend code in this package. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/139.64a0671d.js | AI (source-diff): Standard webpack-minified UI bundle artifact; not obfuscation, stable pattern for this package. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/463.c56e9999.js | AI (source-diff): Webpack bundle for browser UI; network+dynamic-require is normal for bundled frontend code in this package. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/463.c56e9999.js | AI (source-diff): Standard webpack-minified UI bundle artifact; stable pattern for this package. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/383.8bcaf67a.js | AI (source-diff): Network calls and dynamic requires are normal in a bundled browser UI; not dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/383.8bcaf67a.js | AI (source-diff): Webpack-minified UI bundle chunk; expected artifact for @teambit/ui across all versions. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/522.7834818c.js | AI (source-diff): Network calls and dynamic requires are normal in a bundled browser UI; not dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/522.7834818c.js | AI (source-diff): Webpack-minified UI bundle chunk; expected artifact for @teambit/ui across all versions. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'yup' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'qs' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'joi' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @teambit/ui package; Levenshtein match to short unscoped names is a false positive. | ai | |
| phantom-deps | phantom-dep:@teambit/isolator | AI (phantom-deps): Same-org package; phantom-dep heuristic unreliable for monorepo sibling packages. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped runtime dep loaded by convention, not direct import. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'pg' is a false positive. | ai | |
| phantom-deps | phantom-dep:sanitize.css | AI (phantom-deps): CSS asset referenced by convention, not JS import. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): PostCSS referenced in build config; not directly imported in JS. | ai | |
| phantom-deps | phantom-dep:sass | AI (phantom-deps): CSS preprocessor referenced in webpack/rspack config; not directly imported in JS. | ai | |
| phantom-deps | phantom-dep:less | AI (phantom-deps): CSS preprocessor referenced in webpack/rspack config; not directly imported in JS. | ai |
Versions (showing 51 of 59)
| Version | Deps | Published |
|---|---|---|
| 1.0.1064 | 67 / 8 | |
| 1.0.1060 | 67 / 8 | |
| 1.0.1055 | 67 / 8 | |
| 1.0.1052 | 67 / 8 | |
| 1.0.1051 | 67 / 8 | |
| 1.0.1021 | 67 / 8 | |
| 1.0.1013 | 67 / 8 | |
| 1.0.1002 | 67 / 8 | |
| 1.0.1000 | 67 / 8 | |
| 1.0.999 | 67 / 8 | |
| 1.0.995 | 67 / 8 | |
| 1.0.993 | 67 / 8 | |
| 1.0.992 | 67 / 8 | |
| 1.0.989 | 67 / 8 | |
| 1.0.988 | 67 / 8 | |
| 1.0.986 | 67 / 8 | |
| 1.0.983 | 67 / 8 | |
| 1.0.982 | 67 / 8 | |
| 1.0.979 | 67 / 8 | |
| 1.0.975 | 67 / 8 | |
| 1.0.972 | 67 / 8 | |
| 1.0.971 | 67 / 8 | |
| 1.0.970 | 67 / 8 | |
| 1.0.969 | 67 / 8 | |
| 1.0.968 | 67 / 8 | |
| 1.0.965 | 67 / 8 | |
| 1.0.964 | 67 / 8 | |
| 1.0.962 | 67 / 8 | |
| 1.0.958 | 67 / 8 | |
| 1.0.954 | 67 / 8 | |
| 1.0.950 | 67 / 8 | |
| 1.0.943 | 67 / 8 | |
| 1.0.937 | 67 / 8 | |
| 1.0.935 | 67 / 8 | |
| 1.0.931 | 67 / 8 | |
| 1.0.930 | 67 / 8 | |
| 1.0.929 | 67 / 8 | |
| 1.0.927 | 67 / 8 | |
| 1.0.925 | 67 / 8 | |
| 1.0.921 | 67 / 8 | |
| 1.0.920 | 67 / 8 | |
| 1.0.916 | 67 / 8 | |
| 1.0.914 | 67 / 8 | |
| 1.0.913 | 67 / 8 | |
| 1.0.891 | 64 / 8 | |
| 1.0.873 | 77 / 11 | |
| 1.0.858 | 77 / 11 | |
| 1.0.856 | 77 / 11 | |
| 1.0.840 | 77 / 11 | |
| 1.0.827 | 77 / 11 | |
| 1.0.824 | 77 / 11 |
v1.0.1064
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1060
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1055
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1052
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1051
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.921
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.920
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.916
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.914
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.913
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.891
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.873
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.858
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.856
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.840
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.827
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.824
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.