@tscircuit/capacity-autorouter
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:@tscircuit/dataset-srj24 | AI (npm-metadata): First-party tscircuit dataset repo used only in devDependencies for benchmarking. | ai | |
| npm-metadata | url-dep:@tsci/0hmX.45-degree-trace-srj23 | AI (npm-metadata): Dev-only test dataset dep from tscircuit's own org, stable pattern. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-frequency legitimate publisher with 677 versions in registry. | ai | |
| npm-metadata | url-dep:@tscircuit/length-matching-solver | AI (npm-metadata): Dev-only dep from tscircuit's own org. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is an internal tscircuit git package, not an unrelated third party. | ai | |
| dependencies | unvetted-dep:tiny-hypergraph-poly | AI (dependencies): Pinned-commit first-party tscircuit repo, consistent with rest of package's dep pattern. | ai | |
| dependencies | unvetted-dep:pcb-poly-hyper-graph | AI (dependencies): Pinned-commit first-party tscircuit repo, consistent with rest of package's dep pattern. | ai | |
| dependencies | unvetted-dep:high-density-repair02 | AI (dependencies): First-party tscircuit org repo, same pattern as other pinned git deps here. | ai | |
| phantom-deps | phantom-dep:high-density-dataset-z04 | AI (phantom-deps): Used via config/data reference, not direct import; heuristic FP. | ai | |
| dependencies | unvetted-dep:high-density-dataset-z04 | AI (dependencies): First-party tscircuit dataset repo pulled via git URL, benign build data. | ai | |
| phantom-deps | phantom-dep:stack-svgs | AI (phantom-deps): Used via config/build tooling, false positive for direct-import heuristic. | ai | |
| npm-metadata | url-dep:@tsci/0hmX.multi-component-dataset-srj01 | AI (npm-metadata): Same-org dev-only dataset dep, SHA-pinned; recurring pattern across this package's releases. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj20-partial-bga-breakouts | AI (npm-metadata): devDep pointing to tscircuit org's own dataset repo; consistent with established pattern across all versions. | ai | |
| npm-metadata | url-dep:@tscircuit/high-density-a01 | AI (npm-metadata): devDep pointing to tscircuit org's own repo; consistent with established pattern. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj19-bga-passive-overlays | AI (npm-metadata): devDep pointing to tscircuit org's own dataset repo; consistent with established pattern across all versions. | ai | |
| npm-metadata | url-dep:@tscircuit/autorouting-dataset-01 | AI (npm-metadata): devDependency only; tscircuit org repo matching publisher identity; same pattern as other accepted URL deps in this package. | ai | |
| npm-metadata | url-dep:dataset-srj18 | AI (npm-metadata): devDependency only; tscircuit org repo matching publisher identity; same pattern as other accepted URL deps in this package. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj16-bga-breakouts | AI (npm-metadata): devDependency SHA-pinned to tscircuit org's own repo; same pattern as all other accepted url-deps in this package. | ai | |
| npm-metadata | url-dep:zdwiel-dataset | AI (npm-metadata): devDependency benchmark dataset pinned by SHA; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tscircuit/fixed-via-hypergraph-solver | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-repair02 | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:tiny-hypergraph-poly | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:pcb-poly-hyper-graph | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tscircuit/rectdiff | AI (npm-metadata): devDependency from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tsci/tscircuit.dataset-srj12-bus-routing | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tsci/seveibar.dataset-srj13 | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-dataset-z04 | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:@tscircuit/dataset-srj05 | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:dataset-srj11-45-degree | AI (npm-metadata): devDependency test dataset from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-repair03 | AI (npm-metadata): devDependency test fixture from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:high-density-repair01 | AI (npm-metadata): devDependency test fixture from tscircuit org; not shipped to consumers. | ai | |
| npm-metadata | url-dep:tiny-hypergraph | AI (npm-metadata): devDependency test fixture from tscircuit org; not shipped to consumers. | ai | |
| phantom-deps | phantom-dep:bun-match-svg | AI (phantom-deps): Likely used in test/build scripts referenced via config rather than direct import; stable FP. | ai | |
| phantom-deps | phantom-dep:fast-json-stable-stringify | AI (phantom-deps): Listed as a runtime dep in package.json; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:object-hash | AI (phantom-deps): Listed as a runtime dep in package.json; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 100 of 716)
| Version | Deps | Published |
|---|---|---|
| 0.0.721 | 3 / 71 | |
| 0.0.720 | 3 / 71 | |
| 0.0.719 | 3 / 71 | |
| 0.0.718 | 3 / 71 | |
| 0.0.717 | 3 / 71 | |
| 0.0.716 | 3 / 71 | |
| 0.0.715 | 3 / 71 | |
| 0.0.714 | 3 / 71 | |
| 0.0.713 | 3 / 71 | |
| 0.0.712 | 3 / 71 | |
| 0.0.711 | 3 / 71 | |
| 0.0.710 | 3 / 71 | |
| 0.0.709 | 3 / 71 | |
| 0.0.708 | 3 / 71 | |
| 0.0.707 | 3 / 71 | |
| 0.0.706 | 3 / 71 | |
| 0.0.705 | 3 / 71 | |
| 0.0.704 | 3 / 71 | |
| 0.0.703 | 3 / 71 | |
| 0.0.702 | 3 / 71 | |
| 0.0.701 | 3 / 71 | |
| 0.0.700 | 3 / 71 | |
| 0.0.699 | 3 / 71 | |
| 0.0.698 | 3 / 71 | |
| 0.0.697 | 3 / 71 | |
| 0.0.696 | 3 / 70 | |
| 0.0.695 | 3 / 69 | |
| 0.0.694 | 3 / 69 | |
| 0.0.693 | 3 / 69 | |
| 0.0.692 | 3 / 69 | |
| 0.0.691 | 3 / 69 | |
| 0.0.690 | 3 / 69 | |
| 0.0.689 | 3 / 69 | |
| 0.0.688 | 3 / 69 | |
| 0.0.687 | 3 / 69 | |
| 0.0.686 | 3 / 69 | |
| 0.0.685 | 3 / 69 | |
| 0.0.684 | 3 / 69 | |
| 0.0.683 | 3 / 69 | |
| 0.0.682 | 3 / 69 | |
| 0.0.681 | 3 / 69 | |
| 0.0.680 | 3 / 69 | |
| 0.0.679 | 3 / 69 | |
| 0.0.678 | 3 / 69 | |
| 0.0.677 | 3 / 69 | |
| 0.0.676 | 3 / 69 | |
| 0.0.675 | 3 / 69 | |
| 0.0.674 | 3 / 69 | |
| 0.0.673 | 3 / 69 | |
| 0.0.672 | 3 / 69 | |
| 0.0.671 | 3 / 69 | |
| 0.0.670 | 3 / 69 | |
| 0.0.669 | 3 / 68 | |
| 0.0.668 | 3 / 68 | |
| 0.0.667 | 3 / 68 | |
| 0.0.666 | 3 / 68 | |
| 0.0.665 | 3 / 68 | |
| 0.0.664 | 3 / 68 | |
| 0.0.663 | 3 / 68 | |
| 0.0.662 | 3 / 68 | |
| 0.0.661 | 3 / 68 | |
| 0.0.660 | 3 / 67 | |
| 0.0.659 | 3 / 67 | |
| 0.0.658 | 3 / 67 | |
| 0.0.657 | 3 / 66 | |
| 0.0.656 | 3 / 66 | |
| 0.0.655 | 3 / 66 | |
| 0.0.654 | 3 / 66 | |
| 0.0.653 | 3 / 66 | |
| 0.0.652 | 3 / 66 | |
| 0.0.651 | 3 / 66 | |
| 0.0.650 | 3 / 66 | |
| 0.0.649 | 3 / 66 | |
| 0.0.648 | 3 / 66 | |
| 0.0.647 | 3 / 66 | |
| 0.0.646 | 3 / 66 | |
| 0.0.645 | 3 / 66 | |
| 0.0.644 | 3 / 66 | |
| 0.0.643 | 3 / 66 | |
| 0.0.642 | 3 / 66 | |
| 0.0.641 | 3 / 66 | |
| 0.0.640 | 3 / 66 | |
| 0.0.639 | 3 / 66 | |
| 0.0.638 | 3 / 66 | |
| 0.0.637 | 3 / 66 | |
| 0.0.636 | 3 / 66 | |
| 0.0.635 | 3 / 66 | |
| 0.0.634 | 3 / 66 | |
| 0.0.633 | 3 / 66 | |
| 0.0.632 | 3 / 66 | |
| 0.0.631 | 3 / 66 | |
| 0.0.630 | 3 / 66 | |
| 0.0.629 | 3 / 66 | |
| 0.0.628 | 3 / 66 | |
| 0.0.627 | 3 / 66 | |
| 0.0.626 | 3 / 66 | |
| 0.0.625 | 3 / 66 | |
| 0.0.624 | 3 / 66 | |
| 0.0.623 | 3 / 66 | |
| 0.0.622 | 3 / 66 |
v0.0.721
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.720
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.719
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.718
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.717
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.716
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.715
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.714
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.713
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.712
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.711
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.710
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.709
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.708
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.707
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.706
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.705
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.704
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.703
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.702
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.701
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.700
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.699
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.698
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.697
2 findingsDependency '@tscircuit/dataset-srj24' in `devDependencies` points to 'git+https://github.com/tscircuit/dataset-srj24.git#0973fa8a123276ff0f5de1fc7edef31efccb9cc9' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.696
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.695
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.694
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.693
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.692
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.691
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.690
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.689
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.688
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.687
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.686
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.685
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.684
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.683
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.682
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.681
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.680
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.679
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.678
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.677
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.676
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.675
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.674
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.673
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.672
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.671
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.670
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.669
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.668
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.667
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.666
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.665
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.664
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.663
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.662
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.661
2 findingsDependency '@tsci/0hmX.multi-component-dataset-srj01' in `devDependencies` points to 'git+https://github.com/tscircuit/multi-component-dataset-srj01.git#abf9d17c966d466b56ac21b735c6bb6f4518919d' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.660
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.659
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.658
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.657
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.656
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.655
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.654
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.653
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.652
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.651
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.650
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.649
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.648
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.647
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.646
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.645
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.644
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.643
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.642
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.641
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.640
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.639
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.638
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.637
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.636
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.635
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.634
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.633
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.632
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.631
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.630
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.629
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.628
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.627
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.626
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.625
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.624
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.623
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.622
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.