← Home

@tryghost/helpers

Javascript Helpers for working with the Ghost [Content API](https://ghost.org/docs/content-api/)

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalmike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed-stale AI (provenance): Publisher change is stale (2173d), inconsistent with takeover per rule description. ai
provenance missing-githead AI (provenance): Metadata-only regression from a trusted long-running publisher, no malicious code. ai
maintainer-change maintainer-added AI (maintainer-change): Known Ghost core team members, legitimate org maintainer rotation. ai
semgrep semgrep:shady-links-exfil-services AI (semgrep): URL is in a code comment, not executed; documentation reference only. ai
maintainer-change maintainer-removed AI (maintainer-change): Normal maintainer rotation for long-lived official Ghost package. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with TryGhost org's CI/CD migration. ai

Versions (showing 100 of 108)

Version Deps Published
1.1.106 1 / 12
1.1.105 1 / 12
1.1.104 1 / 12
1.1.103 1 / 12
1.1.102 1 / 12
1.1.101 1 / 12
1.1.100 1 / 12
1.1.99 1 / 12
1.1.97 1 / 12
1.1.96 1 / 12
1.1.95 1 / 12
1.1.94 1 / 12
1.1.93 1 / 12
1.1.92 1 / 12
1.1.91 1 / 12
1.1.90 1 / 12
1.1.89 1 / 12
1.1.88 1 / 12
1.1.87 1 / 12
1.1.86 1 / 12
1.1.85 1 / 12
1.1.84 1 / 12
1.1.83 1 / 12
1.1.82 1 / 12
1.1.81 1 / 12
1.1.80 1 / 12
1.1.79 1 / 12
1.1.78 1 / 12
1.1.77 1 / 12
1.1.76 1 / 12
1.1.75 1 / 12
1.1.74 1 / 12
1.1.73 1 / 12
1.1.72 1 / 12
1.1.71 1 / 12
1.1.70 1 / 12
1.1.69 1 / 12
1.1.68 1 / 12
1.1.67 1 / 12
1.1.66 1 / 12
1.1.65 1 / 12
1.1.64 1 / 12
1.1.63 1 / 12
1.1.62 1 / 12
1.1.61 1 / 12
1.1.60 1 / 12
1.1.59 1 / 12
1.1.58 1 / 12
1.1.57 1 / 12
1.1.56 1 / 12
1.1.55 1 / 12
1.1.54 1 / 12
1.1.53 1 / 12
1.1.52 1 / 12
1.1.51 1 / 12
1.1.50 1 / 12
1.1.49 1 / 11
1.1.48 1 / 11
1.1.47 1 / 11
1.1.46 1 / 11
1.1.45 1 / 11
1.1.44 1 / 11
1.1.43 1 / 11
1.1.42 1 / 11
1.1.41 1 / 11
1.1.40 1 / 11
1.1.39 1 / 11
1.1.38 1 / 11
1.1.37 1 / 11
1.1.36 1 / 11
1.1.35 1 / 11
1.1.34 1 / 11
1.1.33 1 / 11
1.1.32 1 / 11
1.1.31 1 / 11
1.1.30 1 / 11
1.1.29 1 / 11
1.1.28 1 / 11
1.1.27 1 / 11
1.1.26 1 / 11
1.1.25 1 / 11
1.1.24 1 / 11
1.1.23 1 / 11
1.1.22 1 / 11
1.1.21 1 / 11
1.1.20 1 / 11
1.1.19 1 / 11
1.1.18 1 / 11
1.1.17 1 / 11
1.1.16 1 / 11
1.1.15 1 / 11
1.1.14 1 / 11
1.1.13 1 / 11
1.1.12 1 / 11
1.1.11 1 / 11
1.1.10 1 / 11
1.1.9 1 / 11
1.1.8 1 / 11
1.1.7 1 / 11
1.1.6 1 / 11
Showing 100 of 108 Next page →

v1.1.91

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.90

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: 9larsons → mike182uk (on 2024-04-25, known maintainer) provenance

This version was published by a different npm account (mike182uk) than the most recent previously approved version (9larsons) on 2024-04-25, but mike182uk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.89

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: binary-koan → 9larsons (on 2023-11-15, known maintainer) provenance

This version was published by a different npm account (9larsons) than the most recent previously approved version (binary-koan) on 2023-11-15, but 9larsons is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.88

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.87

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → binary-koan (on 2023-10-26, known maintainer) provenance

This version was published by a different npm account (binary-koan) than the most recent previously approved version (gargol) on 2023-10-26, but binary-koan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.86

2 findings
MEDIUM Publisher changed: gargol → vershwal (on 2023-09-25, unremoved on npm for 1033d) provenance

This version was published by a different npm account (vershwal) than the most recent previously approved version (gargol) on 2023-09-25. It has since remained available on npm for 1033 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.85

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2023-07-19, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-07-19, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.84

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.83

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → kevinansfield (on 2023-07-05, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (allouis) on 2023-07-05, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.82

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → mike182uk (on 2023-07-04, known maintainer) provenance

This version was published by a different npm account (mike182uk) than the most recent previously approved version (allouis) on 2023-07-04, but mike182uk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.81

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2023-06-12, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2023-06-12, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.80

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → sam-lord (on 2023-06-05, known maintainer) provenance

This version was published by a different npm account (sam-lord) than the most recent previously approved version (daniellockyer) on 2023-06-05, but sam-lord is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.79

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → daniellockyer (on 2023-05-08, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (kevinansfield) on 2023-05-08, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.78

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2023-04-12, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-04-12, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.77

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.76

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → daniellockyer (on 2023-03-09, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (kevinansfield) on 2023-03-09, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.75

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simonbackx → kevinansfield (on 2022-11-29, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (simonbackx) on 2022-11-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.74

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simonbackx → kevinansfield (on 2022-09-19, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (simonbackx) on 2022-09-19, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.73

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → simonbackx (on 2022-09-06, known maintainer) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (gargol) on 2022-09-06, but simonbackx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.72

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → rishabhgrg (on 2022-08-05, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (gargol) on 2022-08-05, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.71

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → gargol (on 2022-06-01, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (allouis) on 2022-06-01, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.70

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → erisds (on 2022-05-27, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (allouis) on 2022-05-27, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.69

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simonbackx → allouis (on 2022-05-16, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (simonbackx) on 2022-05-16, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.68

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simonbackx → gargol (on 2022-05-16, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (simonbackx) on 2022-05-16, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.67

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.66

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → simonbackx (on 2022-05-09, known maintainer) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (gargol) on 2022-05-09, but simonbackx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.65

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → erisds (on 2022-05-05, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2022-05-05, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.64

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-18, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-18, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.63

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → thibpat (on 2022-04-11, known maintainer) provenance

This version was published by a different npm account (thibpat) than the most recent previously approved version (rishabhgrg) on 2022-04-11, but thibpat is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.62

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → daniellockyer (on 2022-03-24, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (rishabhgrg) on 2022-03-24, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.61

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → rishabhgrg (on 2022-03-15, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (gargol) on 2022-03-15, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.60

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → gargol (on 2022-03-11, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (allouis) on 2022-03-11, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.58

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → gargol (on 2022-03-04, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (allouis) on 2022-03-04, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.55

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → allouis (on 2022-01-20, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (kevinansfield) on 2022-01-20, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.54

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → rishabhgrg (on 2021-11-15, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (kevinansfield) on 2021-11-15, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.53

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2021-11-08, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2021-11-08, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.51

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → gargol (on 2021-08-04, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (rishabhgrg) on 2021-08-04, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.50

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → kevinansfield (on 2021-07-29, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (rishabhgrg) on 2021-07-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.49

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → rishabhgrg (on 2021-07-02, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (allouis) on 2021-07-02, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.48

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → allouis (on 2021-06-24, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (kevinansfield) on 2021-06-24, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.47

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → erisds (on 2021-06-18, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (kevinansfield) on 2021-06-18, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.46

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2021-06-09, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2021-06-09, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.45

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2021-05-13, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2021-05-13, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.44

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → kevinansfield (on 2021-05-10, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (allouis) on 2021-05-10, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.43

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → daniellockyer (on 2021-04-16, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (allouis) on 2021-04-16, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.42

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → allouis (on 2021-04-15, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (kevinansfield) on 2021-04-15, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.41

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2021-03-31, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2021-03-31, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.40

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → allouis (on 2021-03-10, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (gargol) on 2021-03-10, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.39

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-03-03, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-03-03, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.38

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-02-08, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-02-08, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.37

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → daniellockyer (on 2021-01-12, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (allouis) on 2021-01-12, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.36

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → daniellockyer (on 2021-01-07, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (allouis) on 2021-01-07, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.35

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: kevinansfield.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.34

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → allouis (on 2020-11-02, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (kevinansfield) on 2020-11-02, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.33

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2020-10-16, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2020-10-16, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.30

2 findings
MEDIUM Publisher changed: gargol → daniellockyer (on 2020-08-13, unremoved on npm for 2171d) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2020-08-13. It has since remained available on npm for 2171 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.29

2 findings
MEDIUM Publisher changed: gargol → daniellockyer (on 2020-08-11, unremoved on npm for 2173d) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2020-08-11. It has since remained available on npm for 2173 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.28

2 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDK/tree/master/packages/helpers/blob/1e6e561fa3892c8e0804aae71c14f5bcbd526c67/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.27

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDK/tree/master/packages/helpers/blob/651a7230dc079ec86bd55671251258d3790befef/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → erisds (on 2020-04-13, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2020-04-13, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.26

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDK/tree/master/packages/helpers/blob/cec7e0183304d3fc44c46f8a518cd20a17bb2de2/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → erisds (on 2020-04-10, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2020-04-10, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.25

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDK/tree/master/packages/helpers/blob/3c5cef14bf54e60f5e9f7e6ad30b43ed283750e2/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

MEDIUM Publisher changed: gargol → daniellockyer (on 2020-04-03, unremoved on npm for 2303d) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2020-04-03. It has since remained available on npm for 2303 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.24

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/dd9183b679fb7ce1e6ea1467829f7c932e55e9b2/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → erisds (on 2020-03-26, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2020-03-26, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.23

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/eeb763ba7ce4150198cfb5de797096961beae759/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2020-03-12, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2020-03-12, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.22

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/d6e5899d104bd8d1b6835a3effdb2596dc7a2694/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → erisds (on 2020-01-21, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2020-01-21, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.21

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/9b9356fbb826cf087c3307291a74967bbe1774bf/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2020-01-15, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2020-01-15, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.20

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/6ab36a2887b325f857a528871d4eea670634aa46/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → erisds (on 2019-12-16, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2019-12-16, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.19

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/282ac72b4f37bc2d3e4f13f5a173662c01146ffd/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → erisds (on 2019-11-12, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (gargol) on 2019-11-12, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.18

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/090c0f21206a402ea18287157535a037db65e4d3/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-10-30, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-10-30, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.17

2 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/029d695d6108710d5b798583cb06f9f35ebbda31/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.16

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/36d96ec8b67ce19296e077cadd0056cb3e36f565/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-10-14, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-10-14, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.15

2 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/e7ddda2c50607cb169486b464d3dceb908eef044/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.14

2 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/78d841f9abeae8631be093eab94dd5eb0a515125/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.13

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/3c167e5917e7a49a0a5fa213a2edd86e084a81a3/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-10-07, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-10-07, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.12

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4195 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/6efaff343b2059daa2c287f2db9c456c7f1a63d6/es/helpers.js#L4195 4193 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4194 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4195 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4196 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4197 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-10-02, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-10-02, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.11

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4194 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/8ec705561ebcc7c2fe0e98460b7641985df54586/es/helpers.js#L4194 4192 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4193 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4194 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4195 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4196 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-09-25, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-09-25, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.10

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4194 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/1c44501e8d63bc195c39c5b02132832fa8fdbe90/es/helpers.js#L4194 4192 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4193 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4194 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4195 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4196 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → aileencgn (on 2019-09-18, known maintainer) provenance

This version was published by a different npm account (aileencgn) than the most recent previously approved version (gargol) on 2019-09-18, but aileencgn is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.9

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4194 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/c9cca1a51eb2a80c72942bf8f1b90812dea95bbc/es/helpers.js#L4194 4192 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4193 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4194 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4195 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4196 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-09-05, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-09-05, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.8

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4194 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/2dcdda385297c5ffd81483271b283164ffa979d0/es/helpers.js#L4194 4192 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4193 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4194 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4195 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4196 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-08-12, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-08-12, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.7

3 findings
HIGH shady-links-exfil-services: es/helpers.js:4194 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/096adf0f7adde4a9c1f6da9ecd1b650571174fff/es/helpers.js#L4194 4192 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4193 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4194 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4195 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4196 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → kevinansfield (on 2019-07-25, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (gargol) on 2019-07-25, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.6

2 findings
HIGH shady-links-exfil-services: es/helpers.js:4194 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) Source: https://github.com/TryGhost/Ghost-SDKs/tree/master/packages/helpers/blob/00bce21c1ac2d45c722b941e6cc88640a5651503/es/helpers.js#L4194 4192 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4193 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4194 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4195 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 4196 | var namedCaptures = result.groups;

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.