← Home

@tryghost/content-api

JavaScript Client Library for the Ghost [Content API](https://ghost.org/docs/content-api/)

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed-stale AI (provenance): Old, long-stable publisher change (2022) for established Ghost SDK package. ai
source-diff source-size-tripled AI (source-diff): Explained by bundler/polyfill dependency changes across many skipped versions. ai
phantom-deps phantom-dep:ghost-ignition AI (phantom-deps): Legitimate Ghost dependency, likely used in build output not scanned source. ai
dependencies unvetted-dep:ghost-ignition AI (dependencies): First-party Ghost ecosystem logging package, not a supply-chain risk. ai
source-diff net-exec-file-transition:umd/content-api.min.js AI (source-diff): Minified bundle output of same polyfill code, not malicious. ai
source-diff net-exec-file-transition:es/content-api.js AI (source-diff): Bundled core-js/axios polyfill code from rollup build, not an injected dropper. ai
provenance publisher-changed AI (provenance): Ghost Foundation migrated to GitHub Actions CI publishing; SLSA attestation confirms supply chain integrity. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal paired with org-level maintainer rotation; no malicious indicators present. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are ghost-org accounts consistent with org-level team rotation. ai

Versions (showing 100 of 121)

Version Deps Published
1.12.10 1 / 17
1.12.9 1 / 17
1.12.8 1 / 17
1.12.7 1 / 17
1.12.6 1 / 17
1.12.5 1 / 17
1.12.4 1 / 17
1.12.3 1 / 17
1.12.2 1 / 17
1.12.0 1 / 17
1.11.28 1 / 17
1.11.27 1 / 17
1.11.26 1 / 17
1.11.25 1 / 17
1.11.24 1 / 17
1.11.23 1 / 17
1.11.22 1 / 17
1.11.21 1 / 17
1.11.20 1 / 17
1.11.19 1 / 17
1.11.18 1 / 17
1.11.17 1 / 17
1.11.16 1 / 17
1.11.15 1 / 17
1.11.14 1 / 17
1.11.13 1 / 17
1.11.12 1 / 17
1.11.11 1 / 17
1.11.10 1 / 17
1.11.9 1 / 17
1.11.8 1 / 17
1.11.7 1 / 17
1.11.6 1 / 17
1.11.5 1 / 17
1.11.4 1 / 17
1.11.3 1 / 17
1.11.2 1 / 17
1.11.1 1 / 17
1.11.0 1 / 17
1.10.1 1 / 17
1.10.0 1 / 17
1.9.8 1 / 16
1.9.7 1 / 16
1.9.6 1 / 16
1.9.5 1 / 16
1.9.4 1 / 16
1.9.3 1 / 16
1.9.2 1 / 16
1.9.1 1 / 16
1.9.0 1 / 16
1.8.0 1 / 15
1.7.3 1 / 15
1.7.2 1 / 15
1.7.1 1 / 15
1.7.0 1 / 15
1.6.3 1 / 15
1.6.2 1 / 15
1.6.1 1 / 15
1.6.0 1 / 15
1.5.17 1 / 15
1.5.16 1 / 15
1.5.15 1 / 15
1.5.14 1 / 15
1.5.13 1 / 15
1.5.12 1 / 15
1.5.11 1 / 15
1.5.10 1 / 14
1.5.9 1 / 14
1.5.8 1 / 14
1.5.7 1 / 14
1.5.6 1 / 14
1.5.5 1 / 14
1.5.4 1 / 14
1.5.3 1 / 14
1.5.2 1 / 14
1.5.1 1 / 14
1.5.0 1 / 14
1.4.15 1 / 14
1.4.14 1 / 14
1.4.13 1 / 14
1.4.12 1 / 14
1.4.11 1 / 14
1.4.10 1 / 14
1.4.9 1 / 14
1.4.8 1 / 14
1.4.7 1 / 14
1.4.6 1 / 14
1.4.5 1 / 14
1.4.4 1 / 14
1.4.3 1 / 14
1.4.2 1 / 14
1.4.1 1 / 14
1.4.0 1 / 14
1.3.11 1 / 14
1.3.10 1 / 14
1.3.9 1 / 14
1.3.8 2 / 14
1.3.7 2 / 14
1.3.6 2 / 14
1.3.5 2 / 14
Showing 100 of 121 Next page →

v1.12.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.12.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.21

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: binary-koan → mike182uk (on 2024-04-25, known maintainer) provenance

This version was published by a different npm account (mike182uk) than the most recent previously approved version (binary-koan) on 2024-04-25, but mike182uk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.20

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: binary-koan → 9larsons (on 2023-11-15, known maintainer) provenance

This version was published by a different npm account (9larsons) than the most recent previously approved version (binary-koan) on 2023-11-15, but 9larsons is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.19

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: vershwal → binary-koan (on 2023-10-30, known maintainer) provenance

This version was published by a different npm account (binary-koan) than the most recent previously approved version (vershwal) on 2023-10-30, but binary-koan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.18

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: vershwal → binary-koan (on 2023-10-26, known maintainer) provenance

This version was published by a different npm account (binary-koan) than the most recent previously approved version (vershwal) on 2023-10-26, but binary-koan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.17

2 findings
MEDIUM Publisher changed: gargol → vershwal (on 2023-09-25, unremoved on npm for 1033d) provenance

This version was published by a different npm account (vershwal) than the most recent previously approved version (gargol) on 2023-09-25. It has since remained available on npm for 1033 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.16

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2023-07-19, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-07-19, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.14

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2023-07-05, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2023-07-05, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.13

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → daniellockyer (on 2023-06-15, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (allouis) on 2023-06-15, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.12

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sam-lord → allouis (on 2023-06-12, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (sam-lord) on 2023-06-12, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → sam-lord (on 2023-06-05, known maintainer) provenance

This version was published by a different npm account (sam-lord) than the most recent previously approved version (daniellockyer) on 2023-06-05, but sam-lord is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.10

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lenabaidakova → daniellockyer (on 2023-05-08, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (lenabaidakova) on 2023-05-08, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.9

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → lenabaidakova (on 2023-04-17, known maintainer) provenance

This version was published by a different npm account (lenabaidakova) than the most recent previously approved version (kevinansfield) on 2023-04-17, but lenabaidakova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.8

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2023-04-12, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-04-12, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → daniellockyer (on 2023-03-09, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (kevinansfield) on 2023-03-09, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2022-11-29, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2022-11-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.4

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2022-09-19, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2022-09-19, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.3

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-09-08, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-09-08, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.2

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-09-06, unremoved on npm for 1417d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-09-06. It has since remained available on npm for 1417 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2022-08-05, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2022-08-05, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.11.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-06-01, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-06-01, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.10.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → aileencgn (on 2022-05-30, known maintainer) provenance

This version was published by a different npm account (aileencgn) than the most recent previously approved version (daniellockyer) on 2022-05-30, but aileencgn is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.10.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → erisds (on 2022-05-27, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (daniellockyer) on 2022-05-27, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.8

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2022-05-16, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2022-05-16, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.7

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-05-16, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-05-16, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.6

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-05-12, unremoved on npm for 1534d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-05-12. It has since remained available on npm for 1534 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.5

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2022-05-11, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2022-05-11, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.4

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-05-10, unremoved on npm for 1536d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-05-10. It has since remained available on npm for 1536 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.3

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → simonbackx (on 2022-05-09, unremoved on npm for 1537d) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-05-09. It has since remained available on npm for 1537 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.2

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → erisds (on 2022-05-05, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (daniellockyer) on 2022-05-05, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-19, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-19, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.9.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-18, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-18, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.8.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-12, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-12, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.7.3

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: daniellockyer → thibpat (on 2022-04-11, unremoved on npm for 1565d) provenance

This version was published by a different npm account (thibpat) than the most recent previously approved version (daniellockyer) on 2022-04-11. It has since remained available on npm for 1565 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.2

3 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2022-03-15, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2022-03-15, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.7.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-03-11, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-03-11, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.3

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2022-03-07, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2022-03-07, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.2

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-03-04, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-03-04, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2022-02-23, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2022-02-23, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2022-01-30, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2022-01-30, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.17

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2022-01-20, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2022-01-20, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.16

3 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.15

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2021-11-15, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2021-11-15, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.14

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2021-11-08, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2021-11-08, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.13

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-09-01, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-09-01, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.12

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-08-04, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-08-04, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.11

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2021-07-29, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2021-07-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.10

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2021-07-02, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2021-07-02, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.9

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2021-06-24, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2021-06-24, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.8

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → erisds (on 2021-06-18, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (daniellockyer) on 2021-06-18, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.7

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2021-06-09, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2021-06-09, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.6

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-05-13, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-05-13, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.5

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2021-05-10, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2021-05-10, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.4

3 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.3

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2021-04-15, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2021-04-15, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.2

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2021-03-31, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2021-03-31, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.1

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2021-03-10, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2021-03-10, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.5.0

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-03-05, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-03-05, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.15

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-03-03, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-03-03, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.14

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-02-08, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-02-08, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.13

3 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.12

3 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.11

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: kevinansfield.

HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2020-12-09, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2020-12-09, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.10

3 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.9

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → rishabhgrg (on 2020-11-06, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (daniellockyer) on 2020-11-06, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.8

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2020-11-02, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2020-11-02, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.7

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2020-10-16, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2020-10-16, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.6

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2020-10-13, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2020-10-13, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.5

4 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2020-09-30, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2020-09-30, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.4

3 findings
HIGH Modified file gained network + code execution: es/content-api.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file gained network + code execution: umd/content-api.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: erisds → daniellockyer (on 2020-08-11, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (erisds) on 2020-08-11, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: erisds → gargol (on 2020-08-04, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (erisds) on 2020-08-04, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.10

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: erisds → daniellockyer (on 2020-04-03, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (erisds) on 2020-04-03, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.3.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.