@umijs/bundler-mako
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): 127.0.0.1 is localhost HMR proxy target; not a remote raw IP — stable false positive for this bundler package. | ai |
Versions (showing 51 of 61)
| Version | Deps | Published |
|---|---|---|
| 0.11.15 | 12 / 0 | |
| 0.11.14 | 12 / 0 | |
| 0.11.13 | 12 / 0 | |
| 0.11.12 | 12 / 0 | |
| 0.11.11 | 12 / 0 | |
| 0.11.10 | 12 / 0 | |
| 0.11.9 | 12 / 0 | |
| 0.11.8 | 12 / 0 | |
| 0.11.7 | 12 / 0 | |
| 0.11.6 | 12 / 0 | |
| 0.11.5 | 12 / 0 | |
| 0.11.4 | 12 / 0 | |
| 0.11.3 | 12 / 0 | |
| 0.11.2 | 12 / 0 | |
| 0.11.1 | 12 / 0 | |
| 0.11.0 | 12 / 0 | |
| 0.10.0 | 12 / 0 | |
| 0.9.9 | 12 / 0 | |
| 0.9.8 | 12 / 0 | |
| 0.9.7 | 12 / 0 | |
| 0.9.6 | 12 / 0 | |
| 0.9.5 | 12 / 0 | |
| 0.9.4 | 12 / 0 | |
| 0.9.3 | 12 / 0 | |
| 0.9.2 | 12 / 0 | |
| 0.9.0 | 12 / 0 | |
| 0.8.15 | 12 / 0 | |
| 0.8.14 | 12 / 0 | |
| 0.8.13 | 12 / 0 | |
| 0.8.11 | 11 / 0 | |
| 0.8.10 | 11 / 0 | |
| 0.8.8 | 11 / 0 | |
| 0.8.7 | 11 / 0 | |
| 0.8.6 | 11 / 0 | |
| 0.8.5 | 11 / 0 | |
| 0.8.4 | 11 / 0 | |
| 0.8.3 | 11 / 0 | |
| 0.8.2 | 11 / 0 | |
| 0.8.1 | 11 / 0 | |
| 0.8.0 | 11 / 0 | |
| 0.7.9 | 11 / 0 | |
| 0.7.8 | 11 / 0 | |
| 0.7.7 | 11 / 0 | |
| 0.7.6 | 11 / 0 | |
| 0.7.5 | 11 / 0 | |
| 0.7.4 | 11 / 0 | |
| 0.7.3 | 11 / 0 | |
| 0.7.2 | 11 / 0 | |
| 0.7.1 | 11 / 0 | |
| 0.7.0 | 11 / 0 | |
| 0.6.0 | 11 / 0 |
v0.11.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2025-04-16, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2025-03-11, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2025-02-12, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (xusd320) on 2025-01-16, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (xusd320) on 2025-01-10, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (stormslowly) on 2025-01-02, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.11.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (stormslowly) on 2024-12-27, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-12-19, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (yifankakaxi) on 2024-12-12, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-12-06, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-11-25, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-11-14, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-11-07, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2024-10-25, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-10-16, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-10-14, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-10-10, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (xusd320) on 2024-09-23, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2024-09-10, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2024-09-09, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (yifankakaxi) on 2024-09-05, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (xusd320) on 2024-08-30, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (peachscript) on 2024-08-26, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (peachscript) on 2024-08-23, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2024-08-22, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-08-16, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (yifankakaxi) on 2024-08-08, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (xusd320) on 2024-08-01, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (xusd320) on 2024-07-25, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2024-07-23, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2024-07-19, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sorrycc) than the most recent previously approved version (yifankakaxi) on 2024-07-11, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-07-02, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-06-27, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-06-20, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.7.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-06-20, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.