← Home

@tryghost/image-transform

`npm install @tryghost/image-transform --save`

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Ghost SDK packages historically published without Sigstore provenance; stable pattern for this package. ai
dependencies unvetted-dep:@tryghost/errors AI (dependencies): First-party Ghost Foundation dependency; stable across all versions of this package. ai

Versions (showing 51 of 61)

View all versions
Version Deps Published
1.4.17 2 / 4
1.4.16 2 / 4
1.4.15 2 / 4
1.4.14 2 / 4
1.4.10 2 / 4
1.4.9 3 / 4
1.4.8 3 / 4
1.4.4 3 / 4
1.4.3 3 / 4
1.4.2 2 / 4
1.4.1 3 / 4
1.4.0 3 / 4
1.3.1 3 / 4
1.3.0 3 / 4
1.2.11 3 / 4
1.2.10 3 / 4
1.2.9 3 / 4
1.2.8 3 / 4
1.2.7 3 / 4
1.2.6 3 / 4
1.2.5 3 / 4
1.2.4 3 / 4
1.2.3 4 / 4
1.2.2 4 / 4
1.2.1 4 / 4
1.2.0 4 / 4
1.1.0 4 / 4
1.0.33 4 / 4
1.0.32 4 / 4
1.0.31 4 / 4
1.0.30 4 / 4
1.0.29 4 / 4
1.0.28 4 / 4
1.0.27 4 / 4
1.0.26 4 / 4
1.0.25 4 / 4
1.0.24 4 / 4
1.0.23 4 / 4
1.0.22 4 / 4
1.0.21 4 / 4
1.0.20 4 / 4
1.0.19 4 / 4
1.0.18 4 / 4
1.0.17 4 / 4
1.0.16 4 / 4
1.0.15 4 / 4
1.0.14 4 / 4
1.0.13 4 / 3
1.0.12 4 / 3
1.0.11 4 / 3
1.0.10 4 / 3

v1.4.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: 9larsons → mike182uk (on 2024-04-25, known maintainer) provenance

This version was published by a different npm account (mike182uk) than the most recent previously approved version (9larsons) on 2024-04-25, but mike182uk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.11

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → 9larsons (on 2023-11-15, known maintainer) provenance

This version was published by a different npm account (9larsons) than the most recent previously approved version (daniellockyer) on 2023-11-15, but 9larsons is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.10

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → binary-koan (on 2023-10-30, known maintainer) provenance

This version was published by a different npm account (binary-koan) than the most recent previously approved version (daniellockyer) on 2023-10-30, but binary-koan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.8

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → allouis (on 2023-06-12, known maintainer) provenance

This version was published by a different npm account (allouis) than the most recent previously approved version (daniellockyer) on 2023-06-12, but allouis is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.7

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → daniellockyer (on 2023-05-08, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2023-05-08, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → gargol (on 2023-04-12, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (kevinansfield) on 2023-04-12, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.5

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → kevinansfield (on 2023-03-15, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2023-03-15, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.4

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → daniellockyer (on 2023-03-09, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (kevinansfield) on 2023-03-09, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → kevinansfield (on 2022-11-29, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (rishabhgrg) on 2022-11-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → rishabhgrg (on 2022-08-05, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (gargol) on 2022-08-05, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simonbackx → gargol (on 2022-07-22, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (simonbackx) on 2022-07-22, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → simonbackx (on 2022-05-27, known maintainer) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (daniellockyer) on 2022-05-27, but simonbackx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.33

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → daniellockyer (on 2022-05-24, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2022-05-24, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.31

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.30

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2022-04-21, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2022-04-21, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.28

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.27

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sam-lord → daniellockyer (on 2022-01-18, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (sam-lord) on 2022-01-18, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.25

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.24

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.23

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.19

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → sam-lord (on 2021-11-30, known maintainer) provenance

This version was published by a different npm account (sam-lord) than the most recent previously approved version (daniellockyer) on 2021-11-30, but sam-lord is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.18

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → daniellockyer (on 2021-11-05, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2021-11-05, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.17

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → gargol (on 2021-10-22, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (daniellockyer) on 2021-10-22, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.16

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → daniellockyer (on 2021-10-01, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2021-10-01, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.14

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sam-lord → gargol (on 2021-09-22, known maintainer) provenance

This version was published by a different npm account (gargol) than the most recent previously approved version (sam-lord) on 2021-09-22, but gargol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.13

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: erisds → sam-lord (on 2021-06-17, known maintainer) provenance

This version was published by a different npm account (sam-lord) than the most recent previously approved version (erisds) on 2021-06-17, but sam-lord is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.12

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daniellockyer → erisds (on 2021-06-09, known maintainer) provenance

This version was published by a different npm account (erisds) than the most recent previously approved version (daniellockyer) on 2021-06-09, but erisds is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.11

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gargol → daniellockyer (on 2021-04-19, known maintainer) provenance

This version was published by a different npm account (daniellockyer) than the most recent previously approved version (gargol) on 2021-04-19, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.