← Home

@tryghost/kg-utils

`npm install @tryghost/kg-utils --save`

50
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Monorepo CI publish; gitHead gaps common, no behavior change accompanies it. ai
maintainer-change maintainer-added AI (maintainer-change): Org-managed package with automated CI publisher; maintainer churn expected. ai

Versions (showing 50 of 50)

Version Deps Published
1.1.5 1 / 0
1.1.4 1 / 7
1.1.3 1 / 13
1.1.2 1 / 13
1.1.1 1 / 13
1.1.0 1 / 13
1.0.44 1 / 13
1.0.43 1 / 13
1.0.42 1 / 4
1.0.41 1 / 4
1.0.40 1 / 4
1.0.39 1 / 4
1.0.38 1 / 4
1.0.37 1 / 4
1.0.36 1 / 4
1.0.35 1 / 4
1.0.33 1 / 4
1.0.32 1 / 4
1.0.31 1 / 4
1.0.30 1 / 4
1.0.29 1 / 4
1.0.28 1 / 4
1.0.27 1 / 4
1.0.26 1 / 4
1.0.25 1 / 4
1.0.24 1 / 4
1.0.23 1 / 4
1.0.22 1 / 4
1.0.21 1 / 4
1.0.20 1 / 4
1.0.19 1 / 4
1.0.18 1 / 4
1.0.17 1 / 4
1.0.16 1 / 4
1.0.15 1 / 4
1.0.14 1 / 4
1.0.13 1 / 4
1.0.12 1 / 4
1.0.11 1 / 4
1.0.10 1 / 4
1.0.9 1 / 4
1.0.8 1 / 4
1.0.7 1 / 4
1.0.6 1 / 4
1.0.5 1 / 4
1.0.4 1 / 4
1.0.3 1 / 4
1.0.2 1 / 4
1.0.1 1 / 4
1.0.0 1 / 4

v1.1.5

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v1.1.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.38

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: tmciesco → GitHub Actions (on 2026-02-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (tmciesco) on 2026-02-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.37

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: chrisraible → tmciesco (on 2026-01-22, known maintainer) provenance

This version was published by a different npm account (tmciesco) than the most recent previously approved version (chrisraible) on 2026-01-22, but tmciesco is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.36

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → chrisraible (on 2026-01-15, known maintainer) provenance

This version was published by a different npm account (chrisraible) than the most recent previously approved version (allouis) on 2026-01-15, but chrisraible is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.35

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: allouis → vershwal (on 2026-01-05, known maintainer) provenance

This version was published by a different npm account (vershwal) than the most recent previously approved version (allouis) on 2026-01-05, but vershwal is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.20

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: 9larsons → kevinansfield (on 2023-10-06, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (9larsons) on 2023-10-06, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.18

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → 9larsons (on 2023-08-15, known maintainer) provenance

This version was published by a different npm account (9larsons) than the most recent previously approved version (rishabhgrg) on 2023-08-15, but 9larsons is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.17

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → ronaldlangeveld (on 2023-08-07, known maintainer) provenance

This version was published by a different npm account (ronaldlangeveld) than the most recent previously approved version (rishabhgrg) on 2023-08-07, but ronaldlangeveld is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.16

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sagzy → rishabhgrg (on 2023-05-05, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (sagzy) on 2023-05-05, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.15

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sagzy → lenabaidakova (on 2023-04-26, known maintainer) provenance

This version was published by a different npm account (lenabaidakova) than the most recent previously approved version (sagzy) on 2023-04-26, but lenabaidakova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.14

2 findings
MEDIUM Publisher changed: kevinansfield → sagzy (on 2023-04-03, unremoved on npm for 1209d) provenance

This version was published by a different npm account (sagzy) than the most recent previously approved version (kevinansfield) on 2023-04-03. It has since remained available on npm for 1209 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.12

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rishabhgrg → kevinansfield (on 2023-02-20, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (rishabhgrg) on 2023-02-20, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lenabaidakova → rishabhgrg (on 2023-01-19, known maintainer) provenance

This version was published by a different npm account (rishabhgrg) than the most recent previously approved version (lenabaidakova) on 2023-01-19, but rishabhgrg is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.9

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → lenabaidakova (on 2023-01-18, known maintainer) provenance

This version was published by a different npm account (lenabaidakova) than the most recent previously approved version (kevinansfield) on 2023-01-18, but lenabaidakova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ronaldlangeveld → kevinansfield (on 2022-11-29, known maintainer) provenance

This version was published by a different npm account (kevinansfield) than the most recent previously approved version (ronaldlangeveld) on 2022-11-29, but kevinansfield is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → ronaldlangeveld (on 2022-10-17, known maintainer) provenance

This version was published by a different npm account (ronaldlangeveld) than the most recent previously approved version (kevinansfield) on 2022-10-17, but ronaldlangeveld is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kevinansfield → simonbackx (on 2022-09-06, known maintainer) provenance

This version was published by a different npm account (simonbackx) than the most recent previously approved version (kevinansfield) on 2022-09-06, but simonbackx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.