← Home

@umijs/preset-umi

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sorryccchenshuai2144kuitospeachscriptxiaohuoniyifankakaxixierenyuanxusd320zoomdong07

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Provenance adoption is sparse; not a disqualifier for established packages. ai
maintainer-change maintainer-added AI (maintainer-change): zoomdong07 added to a large, active monorepo team; no other compromise signals present. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are within the @umijs ecosystem and @stagewise/toolbar; consistent with normal UmiJS feature additions. ai
publish-pattern dormant-publish AI (publish-pattern): Large UmiJS monorepo with 526 versions; publisher has established track record with 286 approved packages. ai
dependencies unvetted-dep:@umijs/utils AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/bundler-utils AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/bundler-esbuild AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/babel-preset-umi AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/bundler-utoopack AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/ui AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/history AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/did-you-know AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/es-module-parser AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:less-plugin-resolve AI (dependencies): Known build utility; no malware indicators. ai
dependencies unvetted-dep:current-script-polyfill AI (dependencies): Small polyfill; no malware indicators. ai
dependencies unvetted-dep:click-to-react-component AI (dependencies): Known dev-experience utility; no malware indicators. ai
phantom-deps phantom-dep:babel-plugin-react-compiler AI (phantom-deps): Listed as direct dep in package.json; phantom-dep heuristic false positive. ai
dependencies unvetted-dep:@umijs/bundler-mako AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@stagewise/toolbar AI (dependencies): Dev toolbar utility; no malware indicators. ai
dependencies unvetted-dep:@umijs/core AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/mfsu AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
semgrep semgrep:child-process-import AI (semgrep): Fires in compiled/os-locale — a bundled devDep for locale detection; not a runtime attack surface. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; sparse README/description is expected for internal preset packages. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in compiled vendor bundles (isnumber/queue-microtask); not malicious, standard minified library code. ai
semgrep semgrep:env-bulk-read AI (semgrep): Fires in compiled/body-parser — standard HTTP middleware; env read is benign config pattern. ai

Versions (showing 100 of 188)

Version Deps Published
4.6.57 39 / 12
4.6.55 39 / 12
4.6.49 39 / 12
4.6.48 39 / 12
4.6.46 39 / 12
4.6.44 39 / 12
4.6.42 39 / 12
4.6.27 39 / 12
4.6.25 39 / 12
4.6.24 39 / 12
4.6.19 39 / 12
4.6.17 39 / 12
4.6.16 39 / 12
4.6.15 39 / 12
4.6.14 39 / 12
4.6.13 39 / 12
4.6.5 39 / 12
4.6.4 39 / 12
4.6.3 39 / 12
4.6.0 39 / 12
4.5.0 39 / 12
4.4.12 38 / 12
4.4.11 37 / 12
4.4.10 37 / 12
4.4.9 37 / 12
4.4.8 37 / 12
4.4.7 37 / 12
4.4.6 37 / 12
4.4.5 37 / 12
4.4.4 37 / 12
4.4.3 37 / 12
4.4.2 37 / 12
4.4.1 37 / 12
4.4.0 37 / 12
4.3.36 37 / 12
4.3.35 37 / 12
4.3.34 37 / 12
4.3.33 37 / 12
4.3.32 37 / 12
4.3.31 37 / 12
4.3.30 37 / 12
4.3.29 37 / 12
4.3.28 37 / 12
4.3.27 37 / 12
4.3.26 37 / 12
4.3.25 37 / 12
4.3.24 37 / 12
4.3.23 37 / 12
4.3.22 37 / 12
4.3.21 37 / 12
4.3.20 37 / 12
4.3.19 37 / 12
4.3.18 37 / 12
4.3.17 37 / 12
4.3.16 37 / 12
4.3.15 37 / 12
4.3.14 37 / 12
4.3.13 37 / 12
4.3.12 37 / 12
4.3.11 37 / 12
4.3.10 37 / 12
4.3.9 37 / 12
4.3.8 37 / 12
4.3.7 37 / 12
4.3.6 37 / 12
4.3.5 37 / 12
4.3.4 37 / 12
4.3.3 37 / 12
4.3.2 37 / 12
4.3.1 37 / 12
4.3.0 37 / 12
4.2.15 37 / 12
4.2.14 37 / 12
4.2.13 37 / 12
4.2.12 37 / 12
4.2.11 37 / 12
4.2.10 37 / 12
4.2.9 37 / 12
4.2.8 37 / 12
4.2.7 37 / 12
4.2.6 37 / 12
4.2.5 37 / 12
4.2.4 37 / 12
4.2.3 36 / 12
4.2.2 36 / 12
4.2.1 36 / 12
4.2.0 36 / 12
4.1.10 35 / 12
4.1.9 35 / 12
4.1.8 35 / 12
4.1.7 35 / 12
4.1.6 35 / 12
4.1.5 35 / 12
4.1.4 35 / 12
4.1.3 35 / 12
4.1.2 35 / 12
4.1.1 35 / 12
4.1.0 35 / 12
4.0.90 35 / 12
4.0.89 35 / 12
Showing 100 of 188 Next page →

v4.4.10

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xusd320 → sorrycc (on 2025-04-25, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (xusd320) on 2025-04-25, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.8

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → xusd320 (on 2025-04-21, known maintainer) provenance

This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2025-04-21, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xusd320 → sorrycc (on 2025-02-28, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (xusd320) on 2025-02-28, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.4

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → xusd320 (on 2025-01-02, known maintainer) provenance

This version was published by a different npm account (xusd320) than the most recent previously approved version (stormslowly) on 2025-01-02, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → xusd320 (on 2025-01-02, known maintainer) provenance

This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2025-01-02, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-12-19, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-12-19, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-12-16, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-12-16, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.36

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-12-06, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-12-06, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.35

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → stormslowly (on 2024-11-25, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-11-25, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.32

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-11-14, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-11-14, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.31

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-11-07, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-11-07, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.28

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → peachscript (on 2024-10-25, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2024-10-25, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.27

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-10-16, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-10-16, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.26

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-10-14, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-10-14, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.25

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-10-10, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-10-10, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.24

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-09-26, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-09-26, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.23

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.21

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-09-23, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-09-23, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.19

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-09-05, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-09-05, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.18

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-08-30, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-08-30, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.17

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2024-08-26, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2024-08-26, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.16

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2024-08-26, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2024-08-26, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.15

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → peachscript (on 2024-08-22, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2024-08-22, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.13

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → stormslowly (on 2024-08-16, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-08-16, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.12

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → sorrycc (on 2024-08-08, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (yifankakaxi) on 2024-08-08, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.11

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-08-01, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-08-01, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.9

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2024-07-23, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2024-07-23, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.7

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → peachscript (on 2024-07-19, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (yifankakaxi) on 2024-07-19, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → sorrycc (on 2024-07-12, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (yifankakaxi) on 2024-07-12, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.5

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → yifankakaxi (on 2024-07-12, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (sorrycc) on 2024-07-12, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-07-11, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-07-11, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-07-11, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-07-11, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-06-27, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-06-27, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.12

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-06-20, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-06-20, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.11

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2024-06-14, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2024-06-14, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.9

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → sorrycc (on 2024-06-03, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (yifankakaxi) on 2024-06-03, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → stormslowly (on 2024-05-29, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-05-29, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.4

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → stormslowly (on 2024-05-16, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-05-16, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → yifankakaxi (on 2024-05-14, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (peachscript) on 2024-05-14, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2024-05-11, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2024-05-11, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.90

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.