@things-factory/integration-sftp
Integration With SFTP
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:ftp | AI (phantom-deps): ftp is a legitimate runtime dep for an SFTP integration package; phantom detection is a false positive here. | ai | |
| phantom-deps | phantom-dep:ssh2 | AI (phantom-deps): ssh2 is a legitimate runtime dep used by ssh2-sftp-client; phantom detection is a false positive here. | ai | |
| provenance | no-provenance | AI (provenance): Large established monorepo; lack of provenance is consistent across all versions and not a risk indicator here. | ai |
Versions (showing 51 of 54)
| Version | Deps | Published |
|---|---|---|
| 9.2.33 | 7 / 0 | |
| 9.2.31 | 7 / 0 | |
| 9.2.30 | 7 / 0 | |
| 9.2.29 | 7 / 0 | |
| 9.2.28 | 7 / 0 | |
| 9.2.27 | 7 / 0 | |
| 9.2.25 | 7 / 0 | |
| 9.2.24 | 7 / 0 | |
| 9.2.23 | 7 / 0 | |
| 9.2.22 | 7 / 0 | |
| 9.2.21 | 7 / 0 | |
| 9.2.20 | 7 / 0 | |
| 9.2.19 | 7 / 0 | |
| 9.2.18 | 7 / 0 | |
| 9.2.17 | 7 / 0 | |
| 9.2.16 | 7 / 0 | |
| 9.2.13 | 7 / 0 | |
| 8.0.92 | 7 / 0 | |
| 8.0.90 | 7 / 0 | |
| 8.0.89 | 7 / 0 | |
| 8.0.88 | 7 / 0 | |
| 8.0.87 | 7 / 0 | |
| 6.4.10 | 7 / 0 | |
| 6.4.8 | 7 / 0 | |
| 4.3.819 | 10 / 0 | |
| 4.3.815 | 10 / 0 | |
| 4.3.804 | 10 / 0 | |
| 4.3.798 | 10 / 0 | |
| 4.3.791 | 10 / 0 | |
| 4.3.790 | 10 / 0 | |
| 4.3.755 | 10 / 0 | |
| 4.3.701 | 10 / 0 | |
| 4.3.637 | 7 / 0 | |
| 4.3.616 | 7 / 0 | |
| 4.3.614 | 7 / 0 | |
| 4.3.609 | 7 / 0 | |
| 4.3.595 | 7 / 0 | |
| 4.3.591 | 7 / 0 | |
| 4.3.582 | 7 / 0 | |
| 4.3.581 | 7 / 0 | |
| 4.3.563 | 7 / 0 | |
| 4.3.562 | 7 / 0 | |
| 4.3.550 | 7 / 0 | |
| 4.3.544 | 7 / 0 | |
| 4.3.536 | 7 / 0 | |
| 4.3.535 | 7 / 0 | |
| 4.3.534 | 7 / 0 | |
| 4.3.533 | 7 / 0 | |
| 4.3.526 | 7 / 0 | |
| 4.3.524 | 7 / 0 | |
| 4.3.518 | 7 / 0 |
v9.2.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (heartyoh) on 2026-03-25, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.90
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (wengliang95) on 2026-04-10, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.89
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (wengliang95) on 2026-04-07, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.88
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (nalshya113) on 2026-03-30, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.8
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (nalshya113) on 2026-03-29, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.804
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-04-10, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.798
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-04-02, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.790
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.616
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.614
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.609
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.595
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.591
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.582
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.581
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.563
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.562
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.550
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.544
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.536
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.535
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.534
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.533
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.526
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.524
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.518
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.