@tryghost/helpers
Javascript Helpers for working with the Ghost [Content API](https://ghost.org/docs/content-api/)
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed-stale | AI (provenance): Publisher change is stale (2173d), inconsistent with takeover per rule description. | ai | |
| provenance | missing-githead | AI (provenance): Metadata-only regression from a trusted long-running publisher, no malicious code. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known Ghost core team members, legitimate org maintainer rotation. | ai | |
| semgrep | semgrep:shady-links-exfil-services | AI (semgrep): URL is in a code comment, not executed; documentation reference only. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Normal maintainer rotation for long-lived official Ghost package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with TryGhost org's CI/CD migration. | ai |
Versions (showing 51 of 108)
| Version | Deps | Published |
|---|---|---|
| 1.1.106 | 1 / 12 | |
| 1.1.105 | 1 / 12 | |
| 1.1.104 | 1 / 12 | |
| 1.1.103 | 1 / 12 | |
| 1.1.102 | 1 / 12 | |
| 1.1.101 | 1 / 12 | |
| 1.1.100 | 1 / 12 | |
| 1.1.99 | 1 / 12 | |
| 1.1.97 | 1 / 12 | |
| 1.1.96 | 1 / 12 | |
| 1.1.95 | 1 / 12 | |
| 1.1.94 | 1 / 12 | |
| 1.1.93 | 1 / 12 | |
| 1.1.92 | 1 / 12 | |
| 1.1.91 | 1 / 12 | |
| 1.1.90 | 1 / 12 | |
| 1.1.89 | 1 / 12 | |
| 1.1.88 | 1 / 12 | |
| 1.1.87 | 1 / 12 | |
| 1.1.86 | 1 / 12 | |
| 1.1.85 | 1 / 12 | |
| 1.1.84 | 1 / 12 | |
| 1.1.83 | 1 / 12 | |
| 1.1.82 | 1 / 12 | |
| 1.1.81 | 1 / 12 | |
| 1.1.80 | 1 / 12 | |
| 1.1.79 | 1 / 12 | |
| 1.1.78 | 1 / 12 | |
| 1.1.77 | 1 / 12 | |
| 1.1.76 | 1 / 12 | |
| 1.1.75 | 1 / 12 | |
| 1.1.74 | 1 / 12 | |
| 1.1.73 | 1 / 12 | |
| 1.1.72 | 1 / 12 | |
| 1.1.71 | 1 / 12 | |
| 1.1.70 | 1 / 12 | |
| 1.1.69 | 1 / 12 | |
| 1.1.68 | 1 / 12 | |
| 1.1.67 | 1 / 12 | |
| 1.1.66 | 1 / 12 | |
| 1.1.65 | 1 / 12 | |
| 1.1.64 | 1 / 12 | |
| 1.1.63 | 1 / 12 | |
| 1.1.62 | 1 / 12 | |
| 1.1.61 | 1 / 12 | |
| 1.1.60 | 1 / 12 | |
| 1.1.59 | 1 / 12 | |
| 1.1.58 | 1 / 12 | |
| 1.1.57 | 1 / 12 | |
| 1.1.56 | 1 / 12 | |
| 1.1.55 | 1 / 12 |
v1.1.91
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.90
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mike182uk) than the most recent previously approved version (9larsons) on 2024-04-25, but mike182uk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.89
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (9larsons) than the most recent previously approved version (binary-koan) on 2023-11-15, but 9larsons is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.88
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.87
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (binary-koan) than the most recent previously approved version (gargol) on 2023-10-26, but binary-koan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.86
2 findingsThis version was published by a different npm account (vershwal) than the most recent previously approved version (gargol) on 2023-09-25. It has since remained available on npm for 1033 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.85
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-07-19, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.84
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.83
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kevinansfield) than the most recent previously approved version (allouis) on 2023-07-05, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.82
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mike182uk) than the most recent previously approved version (allouis) on 2023-07-04, but mike182uk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.81
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2023-06-12, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.80
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sam-lord) than the most recent previously approved version (daniellockyer) on 2023-06-05, but sam-lord is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.79
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (daniellockyer) than the most recent previously approved version (kevinansfield) on 2023-05-08, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.78
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-04-12, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.76
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (daniellockyer) than the most recent previously approved version (kevinansfield) on 2023-03-09, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.75
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kevinansfield) than the most recent previously approved version (simonbackx) on 2022-11-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.74
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kevinansfield) than the most recent previously approved version (simonbackx) on 2022-09-19, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.73
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (simonbackx) than the most recent previously approved version (gargol) on 2022-09-06, but simonbackx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.72
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (gargol) on 2022-08-05, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.71
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gargol) than the most recent previously approved version (allouis) on 2022-06-01, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.70
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (erisds) than the most recent previously approved version (allouis) on 2022-05-27, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.69
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (allouis) than the most recent previously approved version (simonbackx) on 2022-05-16, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.68
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gargol) than the most recent previously approved version (simonbackx) on 2022-05-16, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.67
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.66
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (simonbackx) than the most recent previously approved version (gargol) on 2022-05-09, but simonbackx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.65
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2022-05-05, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.64
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-18, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.63
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (thibpat) than the most recent previously approved version (rishabhgrg) on 2022-04-11, but thibpat is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.62
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (daniellockyer) than the most recent previously approved version (rishabhgrg) on 2022-03-24, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.61
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (gargol) on 2022-03-15, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.60
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gargol) than the most recent previously approved version (allouis) on 2022-03-11, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.58
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gargol) than the most recent previously approved version (allouis) on 2022-03-04, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.55
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (allouis) than the most recent previously approved version (kevinansfield) on 2022-01-20, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.