@tscircuit/capacity-autorouter
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:@tscircuit/dataset-srj24 | AI (npm-metadata): First-party tscircuit dataset repo used only in devDependencies for benchmarking. | ai | |
| npm-metadata | url-dep:@tsci/0hmX.45-degree-trace-srj23 | AI (npm-metadata): Dev-only test dataset dep from tscircuit's own org, stable pattern. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-frequency legitimate publisher with 677 versions in registry. | ai | |
| npm-metadata | url-dep:@tscircuit/length-matching-solver | AI (npm-metadata): Dev-only dep from tscircuit's own org. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is an internal tscircuit git package, not an unrelated third party. | ai | |
| dependencies | unvetted-dep:tiny-hypergraph-poly | AI (dependencies): Pinned-commit first-party tscircuit repo, consistent with rest of package's dep pattern. | ai | |
| dependencies | unvetted-dep:pcb-poly-hyper-graph | AI (dependencies): Pinned-commit first-party tscircuit repo, consistent with rest of package's dep pattern. | ai | |
| dependencies | unvetted-dep:high-density-repair02 | AI (dependencies): First-party tscircuit org repo, same pattern as other pinned git deps here. | ai | |
| phantom-deps | phantom-dep:high-density-dataset-z04 | AI (phantom-deps): Used via config/data reference, not direct import; heuristic FP. | ai | |
| dependencies | unvetted-dep:high-density-dataset-z04 | AI (dependencies): First-party tscircuit dataset repo pulled via git URL, benign build data. | ai | |
| phantom-deps | phantom-dep:stack-svgs | AI (phantom-deps): Used via config/build tooling, false positive for direct-import heuristic. | ai | |
| npm-metadata | url-dep:@tsci/0hmX.multi-component-dataset-srj01 | AI (npm-metadata): Same-org dev-only dataset dep, SHA-pinned; recurring pattern across this package's releases. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj20-partial-bga-breakouts | AI (npm-metadata): devDep pointing to tscircuit org's own dataset repo; consistent with established pattern across all versions. | ai | |
| npm-metadata | url-dep:@tscircuit/high-density-a01 | AI (npm-metadata): devDep pointing to tscircuit org's own repo; consistent with established pattern. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj19-bga-passive-overlays | AI (npm-metadata): devDep pointing to tscircuit org's own dataset repo; consistent with established pattern across all versions. | ai | |
| npm-metadata | url-dep:@tscircuit/autorouting-dataset-01 | AI (npm-metadata): devDependency only; tscircuit org repo matching publisher identity; same pattern as other accepted URL deps in this package. | ai | |
| npm-metadata | url-dep:dataset-srj18 | AI (npm-metadata): devDependency only; tscircuit org repo matching publisher identity; same pattern as other accepted URL deps in this package. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj16-bga-breakouts | AI (npm-metadata): devDependency SHA-pinned to tscircuit org's own repo; same pattern as all other accepted url-deps in this package. | ai | |
| npm-metadata | url-dep:zdwiel-dataset | AI (npm-metadata): devDependency benchmark dataset pinned by SHA; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tscircuit/fixed-via-hypergraph-solver | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-repair02 | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:tiny-hypergraph-poly | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:pcb-poly-hyper-graph | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tscircuit/rectdiff | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj12-bus-routing | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tsci/seveibar.dataset-srj13 | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-dataset-z04 | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tscircuit/dataset-srj05 | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:dataset-srj11-45-degree | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-repair03 | AI (npm-metadata): devDependency test fixture from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-repair01 | AI (npm-metadata): devDependency test fixture from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:tiny-hypergraph | AI (npm-metadata): devDependency test fixture from tscircuit org; not shipped to consumers. | ai | |
| phantom-deps | phantom-dep:bun-match-svg | AI (phantom-deps): Likely used in test/build scripts referenced via config rather than direct import; stable FP. | ai | |
| phantom-deps | phantom-dep:fast-json-stable-stringify | AI (phantom-deps): Listed as a runtime dep in package.json; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:object-hash | AI (phantom-deps): Listed as a runtime dep in package.json; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 51 of 715)
| Version | Deps | Published |
|---|---|---|
| 0.0.720 | 3 / 71 | |
| 0.0.719 | 3 / 71 | |
| 0.0.718 | 3 / 71 | |
| 0.0.717 | 3 / 71 | |
| 0.0.716 | 3 / 71 | |
| 0.0.715 | 3 / 71 | |
| 0.0.714 | 3 / 71 | |
| 0.0.713 | 3 / 71 | |
| 0.0.712 | 3 / 71 | |
| 0.0.711 | 3 / 71 | |
| 0.0.710 | 3 / 71 | |
| 0.0.709 | 3 / 71 | |
| 0.0.708 | 3 / 71 | |
| 0.0.707 | 3 / 71 | |
| 0.0.706 | 3 / 71 | |
| 0.0.705 | 3 / 71 | |
| 0.0.704 | 3 / 71 | |
| 0.0.703 | 3 / 71 | |
| 0.0.702 | 3 / 71 | |
| 0.0.701 | 3 / 71 | |
| 0.0.700 | 3 / 71 | |
| 0.0.699 | 3 / 71 | |
| 0.0.698 | 3 / 71 | |
| 0.0.697 | 3 / 71 | |
| 0.0.696 | 3 / 70 | |
| 0.0.695 | 3 / 69 | |
| 0.0.694 | 3 / 69 | |
| 0.0.693 | 3 / 69 | |
| 0.0.692 | 3 / 69 | |
| 0.0.691 | 3 / 69 | |
| 0.0.690 | 3 / 69 | |
| 0.0.689 | 3 / 69 | |
| 0.0.688 | 3 / 69 | |
| 0.0.687 | 3 / 69 | |
| 0.0.686 | 3 / 69 | |
| 0.0.685 | 3 / 69 | |
| 0.0.684 | 3 / 69 | |
| 0.0.683 | 3 / 69 | |
| 0.0.682 | 3 / 69 | |
| 0.0.681 | 3 / 69 | |
| 0.0.680 | 3 / 69 | |
| 0.0.679 | 3 / 69 | |
| 0.0.678 | 3 / 69 | |
| 0.0.677 | 3 / 69 | |
| 0.0.676 | 3 / 69 | |
| 0.0.675 | 3 / 69 | |
| 0.0.674 | 3 / 69 | |
| 0.0.673 | 3 / 69 | |
| 0.0.672 | 3 / 69 | |
| 0.0.671 | 3 / 69 | |
| 0.0.670 | 3 / 69 |
v0.0.720
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.719
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.718
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.717
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.716
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.715
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.714
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.713
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.712
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.711
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.710
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.709
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.708
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.707
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.706
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.705
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.704
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.703
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.702
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.701
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.700
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.699
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.698
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.697
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.696
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.695
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.694
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.693
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.692
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.691
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.690
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.689
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.688
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.687
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.686
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.685
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.684
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.683
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.682
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.681
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.680
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.679
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.678
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.677
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.676
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.675
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.674
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.673
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.672
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.671
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.670
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.