← Home

@turnkey/react-native-passkey-stamper

43
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

andrewtkr-n-ojack-kearney-tkhq

Keywords

TurnkeyreactnativeiOSAndroidstamper

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Turnkey org migrated publishing to GitHub Actions CI/CD with SLSA attestation; stable pattern for this package going forward. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org-wide shift to automated CI publishing; not indicative of hostile takeover. ai

Versions (showing 43 of 43)

Version Deps Published
1.2.17 5 / 2
1.2.16 5 / 2
1.2.15 5 / 2
1.2.14 5 / 2
1.2.13 5 / 2
1.2.12 5 / 2
1.2.11 5 / 2
1.2.10 5 / 2
1.2.9 5 / 2
1.2.8 5 / 2
1.2.7 5 / 2
1.2.6 5 / 2
1.2.5 5 / 2
1.2.4 5 / 2
1.2.3 5 / 2
1.2.2 5 / 2
1.2.1 5 / 2
1.2.0 5 / 2
1.1.4 5 / 2
1.1.3 5 / 2
1.1.2 5 / 2
1.1.1 5 / 2
1.1.0 5 / 2
1.0.19 5 / 0
1.0.18 5 / 0
1.0.17 5 / 0
1.0.16 5 / 0
1.0.15 5 / 0
1.0.14 5 / 0
1.0.13 5 / 0
1.0.12 5 / 0
1.0.11 5 / 0
1.0.10 5 / 0
1.0.9 5 / 0
1.0.8 5 / 0
1.0.7 5 / 0
1.0.6 5 / 0
1.0.5 5 / 0
1.0.4 5 / 0
1.0.3 5 / 0
1.0.2 5 / 0
1.0.1 5 / 0
1.0.0 5 / 0

v1.2.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.14

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-05-22, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-05-22, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2025-04-28, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-28, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.10

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2025-04-04, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-04, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-03-04, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-03-04, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-02-18, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-02-18, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2025-01-16, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-01-16, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zanetk → moe-dev (on 2024-12-17, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (zanetk) on 2024-12-17, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: r-n-o → zanetk (on 2024-12-05, known maintainer) provenance

This version was published by a different npm account (zanetk) than the most recent previously approved version (r-n-o) on 2024-12-05, but zanetk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.