← Home

@tryghost/content-api

JavaScript Client Library for the Ghost [Content API](https://ghost.org/docs/content-api/)

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed-stale AI (provenance): Old, long-stable publisher change (2022) for established Ghost SDK package. ai
source-diff source-size-tripled AI (source-diff): Explained by bundler/polyfill dependency changes across many skipped versions. ai
phantom-deps phantom-dep:ghost-ignition AI (phantom-deps): Legitimate Ghost dependency, likely used in build output not scanned source. ai
dependencies unvetted-dep:ghost-ignition AI (dependencies): First-party Ghost ecosystem logging package, not a supply-chain risk. ai
source-diff net-exec-file-transition:umd/content-api.min.js AI (source-diff): Minified bundle output of same polyfill code, not malicious. ai
source-diff net-exec-file-transition:es/content-api.js AI (source-diff): Bundled core-js/axios polyfill code from rollup build, not an injected dropper. ai
provenance publisher-changed AI (provenance): Ghost Foundation migrated to GitHub Actions CI publishing; SLSA attestation confirms supply chain integrity. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal paired with org-level maintainer rotation; no malicious indicators present. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are ghost-org accounts consistent with org-level team rotation. ai

Versions (showing 51 of 121)

View all versions
Version Deps Published
1.12.10 1 / 17
1.12.9 1 / 17
1.12.8 1 / 17
1.12.7 1 / 17
1.12.6 1 / 17
1.12.5 1 / 17
1.12.4 1 / 17
1.12.3 1 / 17
1.12.2 1 / 17
1.12.0 1 / 17
1.11.28 1 / 17
1.11.27 1 / 17
1.11.26 1 / 17
1.11.25 1 / 17
1.11.24 1 / 17
1.11.23 1 / 17
1.11.22 1 / 17
1.11.21 1 / 17
1.11.20 1 / 17
1.11.19 1 / 17
1.11.18 1 / 17
1.11.17 1 / 17
1.11.16 1 / 17
1.11.15 1 / 17
1.11.14 1 / 17
1.11.13 1 / 17
1.11.12 1 / 17
1.11.11 1 / 17
1.11.10 1 / 17
1.11.9 1 / 17
1.11.8 1 / 17
1.11.7 1 / 17
1.11.6 1 / 17
1.11.5 1 / 17
1.11.4 1 / 17
1.11.3 1 / 17
1.11.2 1 / 17
1.11.1 1 / 17
1.11.0 1 / 17
1.10.1 1 / 17
1.10.0 1 / 17
1.9.8 1 / 16
1.9.7 1 / 16
1.9.6 1 / 16
1.9.5 1 / 16
1.9.4 1 / 16
1.9.3 1 / 16
1.9.2 1 / 16
1.9.1 1 / 16
1.9.0 1 / 16
1.8.0 1 / 15

v1.12.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.12.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.21

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: binary-koan → mike182uk (on 2024-04-25, known maintainer) provenance

This version was published by a different npm account (mike182uk) than the most recent previously approved version (binary-koan) on 2024-04-25, but mike182uk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.20

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: binary-koan → 9larsons (on 2023-11-15, known maintainer) provenance

This version was published by a different npm account (9larsons) than the most recent previously approved version (binary-koan) on 2023-11-15, but 9larsons is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.19

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: vershwal → binary-koan (on 2023-10-30, known maintainer) provenance

This version was published by a different npm account (binary-koan) than the most recent previously approved version (vershwal) on 2023-10-30, but binary-koan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.18

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: vershwal → binary-koan (on 2023-10-26, known maintainer) provenance

This version was published by a different npm account (binary-koan) than the most recent previously approved version (vershwal) on 2023-10-26, but binary-koan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.17

2 findings
MEDIUM Publisher changed: gargol → vershwal (on 2023-09-25, unremoved on npm for 1033d) provenance

This version was published by a different npm account (vershwal) than the most recent previously approved version (gargol) on 2023-09-25. It has since remained available on npm for 1033 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.16

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2023-07-19, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-07-19, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.14

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2023-07-05, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2023-07-05, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.13

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → daniellockyer (on 2023-06-15, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (allouis) on 2023-06-15, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.12

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sam-lord → allouis (on 2023-06-12, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (sam-lord) on 2023-06-12, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → sam-lord (on 2023-06-05, known maintainer) provenance

This version was published by a different npm account (sam-lord) than the most recent previously approved version (daniellockyer) on 2023-06-05, but sam-lord is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.10

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lenabaidakova → daniellockyer (on 2023-05-08, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (lenabaidakova) on 2023-05-08, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.9

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → lenabaidakova (on 2023-04-17, known maintainer) provenance

This version was published by a different npm account (lenabaidakova) than the most recent previously approved version (kevinansfield) on 2023-04-17, but lenabaidakova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.8

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2023-04-12, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-04-12, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → daniellockyer (on 2023-03-09, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (kevinansfield) on 2023-03-09, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2022-11-29, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2022-11-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.4

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2022-09-19, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2022-09-19, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.3

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-09-08, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-09-08, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.2

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-09-06, unremoved on npm for 1417d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-09-06. It has since remained available on npm for 1417 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2022-08-05, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2022-08-05, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-06-01, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-06-01, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.10.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → aileencgn (on 2022-05-30, known maintainer) provenance

This version was published by a different npm account (aileencgn) than the most recent previously approved version (daniellockyer) on 2022-05-30, but aileencgn is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.10.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → erisds (on 2022-05-27, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (daniellockyer) on 2022-05-27, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.8

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2022-05-16, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2022-05-16, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.7

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-05-16, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-05-16, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.6

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-05-12, unremoved on npm for 1534d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-05-12. It has since remained available on npm for 1534 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.5

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2022-05-11, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2022-05-11, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.4

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-05-10, unremoved on npm for 1536d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-05-10. It has since remained available on npm for 1536 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.3

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-05-09, unremoved on npm for 1537d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-05-09. It has since remained available on npm for 1537 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.2

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → erisds (on 2022-05-05, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (daniellockyer) on 2022-05-05, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-19, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-19, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-18, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-18, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.8.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-12, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-12, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.