← Home

@umijs/renderer-react

@umijs/renderer-react

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sorryccchenshuai2144kuitospeachscriptxiaohuoniyifankakaxixierenyuanxusd320zoomdong07

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Publisher is a known prior maintainer per provenance INFO; not a takeover. ai
maintainer-change maintainer-added AI (maintainer-change): Known maintainer publish, matches umijs org pattern. ai
provenance missing-githead AI (provenance): Minor CI metadata gap for trusted long-running monorepo publisher, no behavioral risk. ai
phantom-deps phantom-dep:@loadable/component AI (phantom-deps): Used via config/build tooling, not a direct import; expected for this package type. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Framework-scoped types; stable pattern for React renderer packages. ai
phantom-deps phantom-dep:@types/react-dom AI (phantom-deps): Framework-scoped types; stable pattern for React renderer packages. ai
phantom-deps phantom-dep:@types/react-router-config AI (phantom-deps): Framework-scoped types; stable pattern for React renderer packages. ai
bogus-package bogus-package AI (bogus-package): Minimal README typical of internal monorepo packages; not indicative of spam. ai

Versions (showing 100 of 280)

Show 26 prereleases
Version Deps Published
4.0.42 5 / 2
4.0.41 5 / 2
4.0.40 5 / 2
4.0.39 5 / 2
4.0.38 5 / 2
4.0.37 5 / 2
4.0.36 5 / 2
4.0.35 5 / 2
4.0.34 5 / 2
4.0.33 5 / 2
4.0.32 5 / 2
4.0.31 5 / 2
4.0.30 5 / 2
4.0.29 4 / 2
4.0.28 4 / 2
4.0.27 4 / 2
4.0.26 4 / 2
4.0.25 4 / 2
4.0.24 4 / 2
4.0.23 4 / 2
4.0.22 4 / 2
4.0.21 4 / 2
4.0.20 4 / 2
4.0.19 4 / 2
4.0.18 4 / 2
4.0.17 4 / 2
4.0.16 4 / 2
4.0.15 4 / 2
4.0.14 4 / 2
4.0.13 4 / 2
4.0.12 4 / 2
4.0.11 4 / 2
4.0.10 4 / 2
4.0.9 4 / 2
4.0.8 4 / 2
4.0.7 3 / 2
4.0.6 3 / 2
4.0.5 3 / 2
4.0.4 3 / 2
4.0.3 3 / 2
4.0.2 3 / 2
4.0.1 3 / 2
4.0.0 3 / 2
3.5.43 5 / 0
3.5.42 5 / 0
3.5.41 5 / 0
3.5.40 5 / 0
3.5.39 5 / 0
3.5.38 5 / 0
3.5.37 5 / 0
3.5.36 5 / 0
3.5.35 5 / 0
3.5.34 5 / 0
3.5.33 5 / 0
3.5.32 5 / 0
3.5.31 5 / 0
3.5.30 5 / 0
3.5.29 5 / 0
3.5.28 5 / 0
3.5.27 5 / 0
3.5.26 5 / 0
3.5.25 5 / 0
3.5.24 5 / 0
3.5.23 5 / 0
3.5.22 5 / 0
3.5.21 5 / 0
3.5.20 5 / 0
3.5.19 5 / 0
3.5.18 5 / 0
3.5.17 5 / 0
3.5.16 5 / 0
3.5.15 5 / 0
3.5.14 5 / 0
3.5.13 5 / 0
3.5.12 5 / 0
3.5.11 5 / 0
3.5.10 5 / 0
3.5.9 5 / 0
3.5.8 5 / 0
3.5.7 5 / 0
3.5.6 5 / 0
3.5.5 5 / 0
3.5.4 5 / 0
3.5.3 5 / 0
3.5.2 5 / 0
3.5.1 5 / 0
3.5.0 5 / 0
3.4.25 5 / 0
3.4.24 5 / 0
3.4.23 5 / 0
3.4.22 5 / 0
3.4.21 5 / 0
3.4.20 5 / 0
3.4.19 5 / 0
3.4.18 5 / 0
3.4.16 5 / 0
3.4.15 5 / 0
3.4.14 5 / 0
3.4.13 5 / 0
3.4.12 5 / 0
Showing 100 of 280 Next page →

v4.0.42

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2023-01-05, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2023-01-05, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.41

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2022-12-29, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2022-12-29, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.40

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2022-12-23, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2022-12-23, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.39

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2022-12-22, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2022-12-22, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.37

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-12-16, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-12-16, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.36

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2022-12-08, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2022-12-08, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.35

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2022-12-08, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2022-12-08, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.34

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → peachscript (on 2022-12-01, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2022-12-01, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.32

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2022-11-17, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2022-11-17, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.31

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2022-11-17, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2022-11-17, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.30

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2022-11-10, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2022-11-10, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.29

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-11-04, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-11-04, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.28

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2022-10-28, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2022-10-28, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.27

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2022-10-27, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2022-10-27, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.26

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2022-10-20, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2022-10-20, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.23

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2022-09-29, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2022-09-29, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.22

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2022-09-22, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2022-09-22, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.20

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2022-09-13, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2022-09-13, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.19

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2022-09-08, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2022-09-08, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.16

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-09-01, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-09-01, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.15

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-08-26, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-08-26, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.14

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → peachscript (on 2022-08-25, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2022-08-25, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.13

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2022-08-18, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2022-08-18, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.12

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-08-11, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-08-11, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.11

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-08-04, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-08-04, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.10

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-08-04, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-08-04, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.9

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2022-07-28, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2022-07-28, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2022-07-21, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2022-07-21, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-07-14, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-07-14, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2022-07-01, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2022-07-01, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2022-06-30, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2022-06-30, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-06-24, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-06-24, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-06-21, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-06-21, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.41

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2023-06-01, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2023-06-01, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.40

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2023-04-13, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2023-04-13, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.39

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2023-03-31, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2023-03-31, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.38

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2023-03-15, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2023-03-15, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.37

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → stormslowly (on 2023-02-16, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (peachscript) on 2023-02-16, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.33

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → peachscript (on 2022-08-25, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2022-08-25, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.29

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-07-14, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-07-14, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.27

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → peachscript (on 2022-07-04, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2022-07-04, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.26

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: peachscript → sorrycc (on 2022-06-08, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (peachscript) on 2022-06-08, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.25

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → peachscript (on 2022-06-02, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (sorrycc) on 2022-06-02, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.5.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.24

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ycjcl868 → sorrycc (on 2021-06-02, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (ycjcl868) on 2021-06-02, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.4.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.21

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ycjcl868 → sorrycc (on 2021-05-18, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (ycjcl868) on 2021-05-18, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.4.20

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → ycjcl868 (on 2021-05-11, known maintainer) provenance

This version was published by a different npm account (ycjcl868) than the most recent previously approved version (sorrycc) on 2021-05-11, but ycjcl868 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.4.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.