← Home

@tryghost/mg-json

28
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Ghost Foundation migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern going forward. ai
provenance missing-githead AI (provenance): CI/CD publish via GitHub Actions with SLSA provenance replaces gitHead as the commit linkage mechanism. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects the monorepo migration cadence, not account takeover; SLSA attestation confirms legitimate CI publish. ai
dependencies unvetted-dep:@tryghost/mg-utils AI (dependencies): First-party Ghost org dependency; stable pattern across this package's versions. ai
dependencies unvetted-dep:node-email-verifier AI (dependencies): Pinned to exact version 4.0.0; no advisories; consistent with package's email-processing purpose. ai

Versions (showing 28 of 28)

Version Deps Published
0.22.2 5 / 1
0.22.1 5 / 1
0.22.0 5 / 1
0.21.0 5 / 1
0.20.0 5 / 1
0.19.3 5 / 1
0.19.2 5 / 1
0.19.1 5 / 1
0.19.0 5 / 1
0.18.0 5 / 1
0.17.0 5 / 1
0.16.0 5 / 1
0.15.0 5 / 1
0.14.0 5 / 1
0.13.0 5 / 1
0.12.0 5 / 1
0.11.13 5 / 3
0.11.12 5 / 3
0.11.11 5 / 3
0.11.10 5 / 3
0.11.9 5 / 3
0.11.8 5 / 3
0.11.7 5 / 3
0.11.6 5 / 3
0.11.5 5 / 3
0.11.4 4 / 3
0.11.3 4 / 3
0.11.2 4 / 3

v0.22.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.