← Home

@tryghost/sodo-search

- Run `pnpm` in Ghost monorepo root - Run `pnpm` in this directory

19
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalmike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is a minor pipeline change for this established Ghost org package. ai
provenance no-provenance AI (provenance): Only ~12% of npm packages have provenance; not a risk signal for established Ghost Foundation package. ai
bogus-package bogus-package AI (bogus-package): Scoped Ghost package; sparse README and missing keywords are typical for internal/specialized libraries, not spam indicators. ai
maintainer-change maintainer-added AI (maintainer-change): Ghost org package published via CI with SLSA provenance; maintainer additions are routine for this org. ai
phantom-deps phantom-dep:@tryghost/content-api AI (phantom-deps): Declared dependency; used in config context, stable false positive for this package. ai
dependencies unvetted-dep:@tryghost/i18n AI (dependencies): Same org scope (TryGhost); workspace dependency, stable internal use. ai
dependencies unvetted-dep:@tryghost/debug AI (dependencies): Same org scope (TryGhost); stable internal dependency. ai
dependencies unvetted-dep:flexsearch AI (dependencies): flexsearch is a legitimate open-source search library; its use here is expected for a search component package. ai
phantom-deps phantom-dep:react AI (phantom-deps): Bundled UMB output; react is consumed at build time, not imported directly at runtime. ai
phantom-deps phantom-dep:@tryghost/debug AI (phantom-deps): Same-org dependency; phantom-dep heuristic is a stable false positive. ai
phantom-deps phantom-dep:@tryghost/i18n AI (phantom-deps): Same-org workspace dependency; phantom-dep heuristic is a stable false positive. ai
phantom-deps phantom-dep:flexsearch AI (phantom-deps): Build-time bundled dependency; phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Same as react — build-time bundle dependency, not a runtime import. ai

Versions (showing 19 of 19)

Version Deps Published
1.8.20 5 / 13
1.8.18 5 / 13
1.8.17 5 / 13
1.8.16 5 / 12
1.8.15 5 / 11
1.8.14 5 / 11
1.8.13 5 / 11
1.8.12 5 / 11
1.8.11 5 / 11
1.8.8 3 / 9
1.8.6 3 / 8
1.8.5 3 / 8
1.8.4 3 / 8
1.8.3 3 / 8
1.8.2 3 / 8
1.8.1 3 / 8
1.7.0 4 / 8
1.6.0 4 / 8
1.5.5 4 / 8

v1.8.20

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.