@things-factory/id-rule-base
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed-stale | AI (provenance): Stale unremoved publish is inconsistent with account takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-wide monorepo maintainer handoff, not isolated to this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same handoff; consistent across sibling packages. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval builds fn from stored rule definition; core to dynamic id-rule feature, stable across versions. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Migration file loader pattern iterating local filesystem paths; not arbitrary user-controlled input. | ai | |
| phantom-deps | phantom-dep:@things-factory/setting-base | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@things-factory/i18n-base | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive here. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 9.2.33 | 6 / 0 | |
| 9.2.30 | 6 / 0 | |
| 9.2.29 | 6 / 0 | |
| 9.2.24 | 6 / 0 | |
| 9.2.19 | 6 / 0 | |
| 9.2.17 | 6 / 0 | |
| 9.2.16 | 6 / 0 | |
| 9.2.13 | 6 / 0 | |
| 9.2.5 | 6 / 0 | |
| 9.1.19 | 6 / 0 | |
| 9.1.13 | 6 / 0 | |
| 9.1.0 | 6 / 0 | |
| 9.0.41 | 6 / 0 | |
| 9.0.36 | 6 / 0 | |
| 9.0.34 | 6 / 0 | |
| 9.0.25 | 6 / 0 | |
| 9.0.24 | 6 / 0 | |
| 9.0.20 | 6 / 0 | |
| 9.0.5 | 6 / 0 | |
| 9.0.2 | 6 / 0 | |
| 9.0.0 | 6 / 0 | |
| 8.0.88 | 6 / 0 | |
| 8.0.87 | 6 / 0 | |
| 8.0.86 | 6 / 0 | |
| 8.0.76 | 6 / 0 | |
| 8.0.75 | 6 / 0 | |
| 8.0.74 | 6 / 0 | |
| 8.0.64 | 6 / 0 | |
| 8.0.63 | 6 / 0 | |
| 6.4.10 | 5 / 0 | |
| 6.4.8 | 5 / 0 | |
| 4.3.815 | 5 / 1 | |
| 4.3.770 | 5 / 1 | |
| 4.3.767 | 5 / 1 | |
| 4.3.764 | 5 / 1 | |
| 4.3.755 | 5 / 1 | |
| 4.3.752 | 5 / 1 | |
| 4.3.743 | 5 / 1 | |
| 4.3.740 | 5 / 1 | |
| 4.3.738 | 5 / 1 | |
| 4.3.734 | 5 / 1 | |
| 4.3.729 | 5 / 1 | |
| 4.3.727 | 5 / 1 | |
| 4.3.725 | 5 / 1 | |
| 4.3.723 | 5 / 1 | |
| 4.3.705 | 5 / 1 | |
| 4.3.695 | 5 / 1 | |
| 4.3.689 | 5 / 1 |
v9.2.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (nalshya113) on 2026-03-19, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v9.1.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (heartyoh) on 2025-10-22, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.64
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.63
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (horwengliang95) on 2025-11-03, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (nalshya113) on 2026-03-29, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.815
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (horwengliang95) than the most recent previously approved version (nalshya113) on 2026-04-16, but horwengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.770
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-02-05, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.767
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-01-29, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.764
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-01-28, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.755
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-01-20, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.752
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-01-15, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.743
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-01-08, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.740
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-01-05, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.738
2 findingsThis version was published by a different npm account (wengliang95) than the most recent previously approved version (heartyoh) on 2025-12-23. It has since remained available on npm for 207 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.734
2 findingsThis version was published by a different npm account (wengliang95) than the most recent previously approved version (heartyoh) on 2025-12-17. It has since remained available on npm for 213 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.729
2 findingsThis version was published by a different npm account (wengliang95) than the most recent previously approved version (heartyoh) on 2025-12-16. It has since remained available on npm for 214 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.727
2 findingsThis version was published by a different npm account (wengliang95) than the most recent previously approved version (heartyoh) on 2025-12-12. It has since remained available on npm for 218 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.725
2 findingsThis version was published by a different npm account (wengliang95) than the most recent previously approved version (heartyoh) on 2025-12-11. It has since remained available on npm for 219 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.723
2 findingsThis version was published by a different npm account (wengliang95) than the most recent previously approved version (heartyoh) on 2025-12-11. It has since remained available on npm for 219 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.705
2 findingsThis version was published by a different npm account (wengliang95) than the most recent previously approved version (heartyoh) on 2025-12-10. It has since remained available on npm for 220 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.695
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (horwengliang95) than the most recent previously approved version (heartyoh) on 2025-11-21, but horwengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.689
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (horwengliang95) than the most recent previously approved version (heartyoh) on 2025-11-02, but horwengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.