@turnkey/viem
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Historical maintainer transition, unchanged since; legitimate org package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-wide Turnkey maintainer rotation, publisher has strong track record. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Consistent with legitimate team transition, no behavioral change in diff. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Used for build/typecheck, not runtime import. | ai | |
| phantom-deps | phantom-dep:@openzeppelin/contracts | AI (phantom-deps): Solidity contracts dependency referenced in hardhat/compile config, not a JS import; false positive for this package. | ai | |
| phantom-deps | phantom-dep:cross-fetch | AI (phantom-deps): cross-fetch is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): @turnkey/viem is intentionally named for the viem library, not a typo of vite. | ai |
Versions (showing 93 of 93)
| Version | Deps | Published |
|---|---|---|
| 0.14.32 | 8 / 4 | |
| 0.14.31 | 8 / 4 | |
| 0.14.30 | 8 / 4 | |
| 0.14.29 | 8 / 4 | |
| 0.14.28 | 8 / 4 | |
| 0.14.27 | 8 / 4 | |
| 0.14.26 | 8 / 4 | |
| 0.14.25 | 8 / 4 | |
| 0.14.24 | 8 / 4 | |
| 0.14.23 | 8 / 4 | |
| 0.14.22 | 8 / 4 | |
| 0.14.21 | 8 / 4 | |
| 0.14.20 | 8 / 4 | |
| 0.14.19 | 8 / 4 | |
| 0.14.18 | 8 / 4 | |
| 0.14.17 | 8 / 4 | |
| 0.14.16 | 8 / 4 | |
| 0.14.15 | 8 / 4 | |
| 0.14.14 | 8 / 4 | |
| 0.14.13 | 8 / 4 | |
| 0.14.12 | 8 / 4 | |
| 0.14.11 | 8 / 4 | |
| 0.14.10 | 8 / 4 | |
| 0.14.9 | 8 / 4 | |
| 0.14.8 | 8 / 4 | |
| 0.14.7 | 8 / 4 | |
| 0.14.6 | 8 / 4 | |
| 0.14.5 | 8 / 4 | |
| 0.14.4 | 8 / 4 | |
| 0.14.3 | 8 / 4 | |
| 0.14.2 | 8 / 4 | |
| 0.14.1 | 8 / 4 | |
| 0.14.0 | 8 / 4 | |
| 0.13.1 | 7 / 4 | |
| 0.13.0 | 7 / 4 | |
| 0.12.1 | 7 / 4 | |
| 0.12.0 | 7 / 4 | |
| 0.11.1 | 7 / 4 | |
| 0.11.0 | 7 / 4 | |
| 0.10.5 | 6 / 4 | |
| 0.10.4 | 6 / 4 | |
| 0.10.3 | 6 / 4 | |
| 0.9.10 | 6 / 4 | |
| 0.9.9 | 6 / 4 | |
| 0.9.8 | 6 / 4 | |
| 0.9.7 | 6 / 4 | |
| 0.9.6 | 6 / 4 | |
| 0.9.5 | 6 / 4 | |
| 0.9.4 | 6 / 4 | |
| 0.9.3 | 6 / 4 | |
| 0.9.2 | 6 / 4 | |
| 0.9.1 | 6 / 4 | |
| 0.9.0 | 6 / 4 | |
| 0.8.0 | 6 / 4 | |
| 0.7.2 | 5 / 4 | |
| 0.7.1 | 5 / 4 | |
| 0.7.0 | 5 / 4 | |
| 0.6.18 | 5 / 4 | |
| 0.6.17 | 5 / 4 | |
| 0.6.16 | 5 / 4 | |
| 0.6.15 | 5 / 4 | |
| 0.6.14 | 5 / 4 | |
| 0.6.13 | 5 / 4 | |
| 0.6.12 | 5 / 4 | |
| 0.6.11 | 5 / 4 | |
| 0.6.10 | 5 / 4 | |
| 0.6.9 | 5 / 4 | |
| 0.6.8 | 6 / 3 | |
| 0.6.7 | 6 / 3 | |
| 0.6.6 | 6 / 3 | |
| 0.6.5 | 6 / 3 | |
| 0.6.4 | 6 / 3 | |
| 0.6.3 | 6 / 3 | |
| 0.6.2 | 6 / 3 | |
| 0.6.1 | 6 / 3 | |
| 0.6.0 | 6 / 3 | |
| 0.5.0 | 6 / 3 | |
| 0.4.31 | 6 / 3 | |
| 0.4.30 | 6 / 3 | |
| 0.4.29 | 6 / 3 | |
| 0.4.28 | 6 / 3 | |
| 0.4.27 | 6 / 3 | |
| 0.4.26 | 6 / 3 | |
| 0.4.25 | 6 / 3 | |
| 0.4.24 | 6 / 3 | |
| 0.4.23 | 6 / 3 | |
| 0.4.22 | 6 / 3 | |
| 0.4.21 | 6 / 3 | |
| 0.4.20 | 6 / 3 | |
| 0.4.19 | 6 / 3 | |
| 0.4.18 | 6 / 3 | |
| 0.4.17 | 6 / 3 | |
| 0.4.16 | 6 / 3 |
v0.14.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.20
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bcturnkey) on 2025-12-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.16
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-11-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.11
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-10-31, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.10
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-10-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andrewtk) than the most recent previously approved version (r-n-o) on 2025-09-10, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.13.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-08-28, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-08-01, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-07-31, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bcturnkey) than the most recent previously approved version (andrewtk) on 2025-06-17, but bcturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bcturnkey) than the most recent previously approved version (moe-dev) on 2025-06-12, but bcturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-06-02, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-05-22, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-28, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-04-27, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-04, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-04-01, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tdawson) than the most recent previously approved version (moe-dev) on 2025-03-11, but tdawson is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-02-18, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-02-12, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2025-01-16, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (tdawson) on 2024-12-09, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zanetk) than the most recent previously approved version (tdawson) on 2024-12-05, but zanetk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tdawson) than the most recent previously approved version (zanetk) on 2024-11-20, but tdawson is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (zanetk) on 2024-11-15, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zanetk) than the most recent previously approved version (moe-dev) on 2024-10-10, but zanetk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andrewtk) than the most recent previously approved version (moe-dev) on 2024-10-03, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (r-n-o) on 2024-09-21, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.31
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (moe-dev) on 2024-09-12, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.29
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (r-n-o) on 2024-08-29, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.28
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (omkar_turnkey) than the most recent previously approved version (r-n-o) on 2024-08-26, but omkar_turnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.27
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (moe-dev) on 2024-08-21, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.26
2 findingsThis version was published by a different npm account than previous versions on 2024-08-16. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.24
2 findingsThis version was published by a different npm account than previous versions on 2024-07-19. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.22
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (jordanturnkey) on 2024-06-26, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.20
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jordanturnkey) than the most recent previously approved version (andrewtk) on 2024-06-20, but jordanturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.4.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.