@tryghost/kg-html-to-lexical
Convert HTML strings into Lexical editor state objects
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Org-managed Ghost package with continued CI provenance; low risk of takeover. | ai | |
| provenance | missing-githead | AI (provenance): CI-published monorepo package; gitHead gaps are common in automated monorepo releases. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Ghost Foundation internal maintainer rotation; kevinansfield is a long-standing trusted publisher. | ai | |
| provenance | publisher-changed | AI (provenance): kevinansfield is a long-standing Ghost Foundation publisher; transition from sanne-san is consistent with org-internal handoff. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Scoped Ghost Foundation package; missing description is a cosmetic issue, not a malware indicator. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Ghost Foundation monorepo package; dormancy reflects migration/restructuring, not suspicious activity. | ai | |
| dependencies | unvetted-dep:@tryghost/kg-default-nodes | AI (dependencies): First-party Ghost monorepo dependency; expected for this package. | ai | |
| dependencies | unvetted-dep:@tryghost/kg-default-transforms | AI (dependencies): First-party Ghost monorepo dependency; expected for this package. | ai |
Versions (showing 51 of 95)
| Version | Deps | Published |
|---|---|---|
| 1.3.5 | 10 / 0 | |
| 1.3.4 | 10 / 6 | |
| 1.3.3 | 10 / 9 | |
| 1.3.2 | 10 / 9 | |
| 1.3.1 | 10 / 9 | |
| 1.3.0 | 10 / 9 | |
| 1.2.45 | 10 / 9 | |
| 1.2.44 | 10 / 9 | |
| 1.2.43 | 10 / 9 | |
| 1.2.42 | 10 / 9 | |
| 1.2.41 | 10 / 9 | |
| 1.2.40 | 10 / 9 | |
| 1.2.39 | 10 / 9 | |
| 1.2.38 | 10 / 7 | |
| 1.2.37 | 10 / 7 | |
| 1.2.36 | 10 / 7 | |
| 1.2.35 | 10 / 7 | |
| 1.2.34 | 10 / 7 | |
| 1.2.33 | 10 / 7 | |
| 1.2.32 | 10 / 7 | |
| 1.2.31 | 10 / 7 | |
| 1.2.30 | 10 / 7 | |
| 1.2.29 | 10 / 7 | |
| 1.2.28 | 10 / 7 | |
| 1.2.27 | 10 / 7 | |
| 1.2.25 | 10 / 7 | |
| 1.2.24 | 10 / 7 | |
| 1.2.23 | 10 / 7 | |
| 1.2.22 | 10 / 7 | |
| 1.2.21 | 10 / 7 | |
| 1.2.20 | 10 / 7 | |
| 1.2.19 | 10 / 7 | |
| 1.2.18 | 10 / 7 | |
| 1.2.17 | 10 / 7 | |
| 1.2.16 | 10 / 7 | |
| 1.2.15 | 10 / 7 | |
| 1.2.14 | 10 / 7 | |
| 1.2.13 | 10 / 7 | |
| 1.2.12 | 10 / 7 | |
| 1.2.11 | 10 / 7 | |
| 1.2.10 | 10 / 7 | |
| 1.2.9 | 10 / 7 | |
| 1.2.8 | 10 / 7 | |
| 1.2.7 | 10 / 7 | |
| 1.2.5 | 10 / 7 | |
| 1.2.4 | 10 / 7 | |
| 1.2.3 | 10 / 7 | |
| 1.2.2 | 10 / 7 | |
| 1.2.1 | 10 / 7 | |
| 1.2.0 | 10 / 7 | |
| 1.1.26 | 10 / 7 |
v1.3.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.4
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v1.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kevinansfield) than the most recent previously approved version (daniellockyer) on 2025-03-03, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (daniellockyer) than the most recent previously approved version (ronaldlangeveld) on 2025-02-17, but daniellockyer is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.26
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ronaldlangeveld) than the most recent previously approved version (kevinansfield) on 2025-02-13, but ronaldlangeveld is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.