@tryghost/mg-wp-api
Export content using the WordPress JSON API, and generate a `zip` file you can import into a Ghost installation.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Ghost Foundation migrated to GitHub Actions CI publishing; SLSA attestation confirms supply chain integrity. | ai | |
| provenance | missing-githead | AI (provenance): Consistent with GitHub Actions CI publish flow for this org; SLSA provenance attestation compensates. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): lodash is a well-established utility library with no malicious indicators; addition is benign. | ai | |
| phantom-deps | phantom-dep:@tryghost/errors | AI (phantom-deps): Same-org scoped dependency; declared in package.json and used internally. | ai | |
| dependencies | unvetted-dep:wpapi | AI (dependencies): Known WP API client; stable dependency for this Ghost migration tool. | ai | |
| dependencies | unvetted-dep:@tryghost/mg-webscraper | AI (dependencies): First-party Ghost migration utility; stable across versions. | ai | |
| dependencies | unvetted-dep:simple-dom | AI (dependencies): Well-known DOM utility; no risk signal for this package. | ai | |
| dependencies | unvetted-dep:@tryghost/debug | AI (dependencies): First-party Ghost Foundation package; stable across versions. | ai | |
| dependencies | unvetted-dep:@tryghost/mg-fs-utils | AI (dependencies): First-party Ghost migration utility; stable across versions. | ai |
Versions (showing 51 of 52)
| Version | Deps | Published |
|---|---|---|
| 0.23.2 | 10 / 1 | |
| 0.23.1 | 10 / 1 | |
| 0.23.0 | 10 / 1 | |
| 0.22.0 | 10 / 1 | |
| 0.21.0 | 11 / 1 | |
| 0.20.3 | 11 / 1 | |
| 0.20.2 | 11 / 1 | |
| 0.20.1 | 12 / 1 | |
| 0.20.0 | 12 / 1 | |
| 0.19.0 | 12 / 1 | |
| 0.18.0 | 13 / 1 | |
| 0.17.0 | 13 / 1 | |
| 0.16.0 | 13 / 1 | |
| 0.15.0 | 12 / 1 | |
| 0.14.0 | 12 / 1 | |
| 0.13.0 | 12 / 1 | |
| 0.12.2 | 12 / 1 | |
| 0.12.1 | 12 / 1 | |
| 0.12.0 | 12 / 1 | |
| 0.11.20 | 12 / 3 | |
| 0.11.19 | 12 / 3 | |
| 0.11.18 | 12 / 3 | |
| 0.11.17 | 12 / 3 | |
| 0.11.16 | 12 / 3 | |
| 0.11.15 | 12 / 3 | |
| 0.11.14 | 12 / 3 | |
| 0.11.13 | 12 / 3 | |
| 0.11.12 | 12 / 3 | |
| 0.11.11 | 12 / 3 | |
| 0.11.10 | 12 / 3 | |
| 0.11.9 | 12 / 3 | |
| 0.11.8 | 12 / 3 | |
| 0.11.7 | 12 / 3 | |
| 0.11.6 | 12 / 3 | |
| 0.11.5 | 12 / 3 | |
| 0.11.4 | 12 / 3 | |
| 0.11.3 | 12 / 3 | |
| 0.11.2 | 12 / 3 | |
| 0.11.1 | 12 / 3 | |
| 0.11.0 | 12 / 3 | |
| 0.10.38 | 12 / 3 | |
| 0.10.37 | 12 / 3 | |
| 0.10.36 | 12 / 3 | |
| 0.10.35 | 11 / 3 | |
| 0.10.34 | 11 / 3 | |
| 0.10.33 | 11 / 3 | |
| 0.10.32 | 11 / 3 | |
| 0.10.31 | 11 / 3 | |
| 0.10.30 | 11 / 3 | |
| 0.10.29 | 9 / 3 | |
| 0.10.28 | 10 / 3 |
v0.23.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.