← Home

@turnkey/viem

93
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

andrewtkr-n-ojack-kearney-tkhq

Keywords

TurnkeyViemcustom accountaccountwalletsigner

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Historical maintainer transition, unchanged since; legitimate org package. ai
maintainer-change maintainer-added AI (maintainer-change): Org-wide Turnkey maintainer rotation, publisher has strong track record. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with legitimate team transition, no behavioral change in diff. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Used for build/typecheck, not runtime import. ai
phantom-deps phantom-dep:@openzeppelin/contracts AI (phantom-deps): Solidity contracts dependency referenced in hardhat/compile config, not a JS import; false positive for this package. ai
phantom-deps phantom-dep:cross-fetch AI (phantom-deps): cross-fetch is a declared runtime dependency; phantom-dep heuristic is a false positive here. ai
typosquat typosquat.levenshtein:vite AI (typosquat): @turnkey/viem is intentionally named for the viem library, not a typo of vite. ai

Versions (showing 93 of 93)

Version Deps Published
0.14.32 8 / 4
0.14.31 8 / 4
0.14.30 8 / 4
0.14.29 8 / 4
0.14.28 8 / 4
0.14.27 8 / 4
0.14.26 8 / 4
0.14.25 8 / 4
0.14.24 8 / 4
0.14.23 8 / 4
0.14.22 8 / 4
0.14.21 8 / 4
0.14.20 8 / 4
0.14.19 8 / 4
0.14.18 8 / 4
0.14.17 8 / 4
0.14.16 8 / 4
0.14.15 8 / 4
0.14.14 8 / 4
0.14.13 8 / 4
0.14.12 8 / 4
0.14.11 8 / 4
0.14.10 8 / 4
0.14.9 8 / 4
0.14.8 8 / 4
0.14.7 8 / 4
0.14.6 8 / 4
0.14.5 8 / 4
0.14.4 8 / 4
0.14.3 8 / 4
0.14.2 8 / 4
0.14.1 8 / 4
0.14.0 8 / 4
0.13.1 7 / 4
0.13.0 7 / 4
0.12.1 7 / 4
0.12.0 7 / 4
0.11.1 7 / 4
0.11.0 7 / 4
0.10.5 6 / 4
0.10.4 6 / 4
0.10.3 6 / 4
0.9.10 6 / 4
0.9.9 6 / 4
0.9.8 6 / 4
0.9.7 6 / 4
0.9.6 6 / 4
0.9.5 6 / 4
0.9.4 6 / 4
0.9.3 6 / 4
0.9.2 6 / 4
0.9.1 6 / 4
0.9.0 6 / 4
0.8.0 6 / 4
0.7.2 5 / 4
0.7.1 5 / 4
0.7.0 5 / 4
0.6.18 5 / 4
0.6.17 5 / 4
0.6.16 5 / 4
0.6.15 5 / 4
0.6.14 5 / 4
0.6.13 5 / 4
0.6.12 5 / 4
0.6.11 5 / 4
0.6.10 5 / 4
0.6.9 5 / 4
0.6.8 6 / 3
0.6.7 6 / 3
0.6.6 6 / 3
0.6.5 6 / 3
0.6.4 6 / 3
0.6.3 6 / 3
0.6.2 6 / 3
0.6.1 6 / 3
0.6.0 6 / 3
0.5.0 6 / 3
0.4.31 6 / 3
0.4.30 6 / 3
0.4.29 6 / 3
0.4.28 6 / 3
0.4.27 6 / 3
0.4.26 6 / 3
0.4.25 6 / 3
0.4.24 6 / 3
0.4.23 6 / 3
0.4.22 6 / 3
0.4.21 6 / 3
0.4.20 6 / 3
0.4.19 6 / 3
0.4.18 6 / 3
0.4.17 6 / 3
0.4.16 6 / 3

v0.14.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.20

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: bcturnkey → GitHub Actions (on 2025-12-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bcturnkey) on 2025-12-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.14.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.16

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: r-n-o → GitHub Actions (on 2025-11-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-11-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.14.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.11

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: r-n-o → GitHub Actions (on 2025-10-31, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-10-31, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.14.10

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: r-n-o → GitHub Actions (on 2025-10-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-10-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.14.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: r-n-o → andrewtk (on 2025-09-10, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (r-n-o) on 2025-09-10, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.13.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: bcturnkey → r-n-o (on 2025-08-28, known maintainer) provenance

This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-08-28, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: bcturnkey → r-n-o (on 2025-08-01, known maintainer) provenance

This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-08-01, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.10.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: bcturnkey → r-n-o (on 2025-07-31, known maintainer) provenance

This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-07-31, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → bcturnkey (on 2025-06-17, known maintainer) provenance

This version was published by a different npm account (bcturnkey) than the most recent previously approved version (andrewtk) on 2025-06-17, but bcturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → bcturnkey (on 2025-06-12, known maintainer) provenance

This version was published by a different npm account (bcturnkey) than the most recent previously approved version (moe-dev) on 2025-06-12, but bcturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-06-02, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-06-02, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-05-22, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-05-22, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2025-04-28, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-28, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.8.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-04-27, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-04-27, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2025-04-04, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-04, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2025-04-01, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-01, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.15

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → tdawson (on 2025-03-11, known maintainer) provenance

This version was published by a different npm account (tdawson) than the most recent previously approved version (moe-dev) on 2025-03-11, but tdawson is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.12

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-02-18, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-02-18, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → moe-dev (on 2025-02-12, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-02-12, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2025-01-16, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-01-16, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tdawson → moe-dev (on 2024-12-09, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (tdawson) on 2024-12-09, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tdawson → zanetk (on 2024-12-05, known maintainer) provenance

This version was published by a different npm account (zanetk) than the most recent previously approved version (tdawson) on 2024-12-05, but zanetk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zanetk → tdawson (on 2024-11-20, known maintainer) provenance

This version was published by a different npm account (tdawson) than the most recent previously approved version (zanetk) on 2024-11-20, but tdawson is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zanetk → moe-dev (on 2024-11-15, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (zanetk) on 2024-11-15, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → zanetk (on 2024-10-10, known maintainer) provenance

This version was published by a different npm account (zanetk) than the most recent previously approved version (moe-dev) on 2024-10-10, but zanetk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → andrewtk (on 2024-10-03, known maintainer) provenance

This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2024-10-03, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: r-n-o → moe-dev (on 2024-09-21, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (r-n-o) on 2024-09-21, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.31

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → r-n-o (on 2024-09-12, known maintainer) provenance

This version was published by a different npm account (r-n-o) than the most recent previously approved version (moe-dev) on 2024-09-12, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.29

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: r-n-o → moe-dev (on 2024-08-29, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (r-n-o) on 2024-08-29, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.28

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: r-n-o → omkar_turnkey (on 2024-08-26, known maintainer) provenance

This version was published by a different npm account (omkar_turnkey) than the most recent previously approved version (r-n-o) on 2024-08-26, but omkar_turnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.27

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: moe-dev → r-n-o (on 2024-08-21, known maintainer) provenance

This version was published by a different npm account (r-n-o) than the most recent previously approved version (moe-dev) on 2024-08-21, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.26

2 findings
HIGH Publisher changed: moe-dev → omkar_turnkey (on 2024-08-16) provenance

This version was published by a different npm account than previous versions on 2024-08-16. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.24

2 findings
HIGH Publisher changed: moe-dev → zanetk (on 2024-07-19) provenance

This version was published by a different npm account than previous versions on 2024-07-19. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.22

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jordanturnkey → moe-dev (on 2024-06-26, known maintainer) provenance

This version was published by a different npm account (moe-dev) than the most recent previously approved version (jordanturnkey) on 2024-06-26, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.20

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: andrewtk → jordanturnkey (on 2024-06-20, known maintainer) provenance

This version was published by a different npm account (jordanturnkey) than the most recent previously approved version (andrewtk) on 2024-06-20, but jordanturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.