@wix/auto_sdk_suppliers-hub_marketplace-products
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/internal/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-CUkTaKFE.d.ts | AI (source-diff): TypeScript declaration file with long interface definitions from tsup bundling; not executable code. | ai | |
| source-diff | obfuscated-file:build/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-CUkTaKFE.d.ts | AI (source-diff): TypeScript declaration file with long interface definitions from tsup bundling; not executable code. | ai | |
| source-diff | obfuscated-file:build/internal/es/suppliershub-marketplace-v1-product-marketplace-products.universal-CUkTaKFE.d.mts | AI (source-diff): TypeScript declaration file with long interface definitions from tsup bundling; not executable code. | ai | |
| source-diff | obfuscated-file:build/es/suppliershub-marketplace-v1-product-marketplace-products.universal-CUkTaKFE.d.mts | AI (source-diff): TypeScript declaration file with long interface definitions from tsup bundling; not executable code. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-D96ANNAc.d.ts | AI (source-diff): TypeScript declaration file with long interface definitions; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/internal/es/suppliershub-marketplace-v1-product-marketplace-products.universal-D96ANNAc.d.mts | AI (source-diff): TypeScript declaration file with long interface definitions; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-D96ANNAc.d.ts | AI (source-diff): TypeScript declaration file with long interface definitions; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/es/suppliershub-marketplace-v1-product-marketplace-products.universal-D96ANNAc.d.mts | AI (source-diff): TypeScript declaration file with long interface definitions; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/internal/es/suppliershub-marketplace-v1-product-marketplace-products.universal-DNa17b_j.d.mts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/internal/es/meta.d.mts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/es/meta.d.mts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-DNa17b_j.d.ts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/meta.d.ts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/cjs/meta.d.ts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/es/suppliershub-marketplace-v1-product-marketplace-products.universal-DNa17b_j.d.mts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-DNa17b_j.d.ts | AI (source-diff): TypeScript declaration file; standard Wix SDK build artifact. | ai | |
| source-diff | obfuscated-file:build/es/suppliershub-marketplace-v1-product-marketplace-products.universal-C617LcEz.d.mts | AI (source-diff): Long-line TypeScript declaration file from tsup bundler; standard for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/suppliershub-marketplace-v1-product-marketplace-products.universal-C617LcEz.d.mts | AI (source-diff): Long-line TypeScript declaration file from tsup bundler; standard for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-C617LcEz.d.ts | AI (source-diff): Long-line TypeScript declaration file from tsup bundler; standard for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-C617LcEz.d.ts | AI (source-diff): Long-line TypeScript declaration file from tsup bundler; standard for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-DyEzGTH0.d.ts | AI (source-diff): TypeScript declaration file; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/es/index.d.mts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/index.d.mts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/es/index.typings.d.mts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/index.typings.d.mts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/es/suppliershub-marketplace-v1-product-marketplace-products.universal-DyEzGTH0.d.mts | AI (source-diff): TypeScript declaration file; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/suppliershub-marketplace-v1-product-marketplace-products.universal-DyEzGTH0.d.mts | AI (source-diff): TypeScript declaration file; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/cjs/index.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/index.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/cjs/index.typings.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/index.typings.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-DyEzGTH0.d.ts | AI (source-diff): TypeScript declaration file; standard tsup SDK build output for Wix packages. | ai | |
| source-diff | obfuscated-file:build/es/suppliershub-marketplace-v1-product-marketplace-products.universal-BxkB6MC-.d.mts | AI (source-diff): Generated TypeScript declaration file with long lines from large type unions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-BxkB6MC-.d.ts | AI (source-diff): Generated TypeScript declaration file with long lines from large type unions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-BxkB6MC-.d.ts | AI (source-diff): Generated TypeScript declaration file with long lines from large type unions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/internal/es/suppliershub-marketplace-v1-product-marketplace-products.universal-BxkB6MC-.d.mts | AI (source-diff): Generated TypeScript declaration file with long lines from large type unions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/internal/es/suppliershub-marketplace-v1-product-marketplace-products.universal-By2yn-nV.d.mts | AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-By2yn-nV.d.ts | AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/cjs/suppliershub-marketplace-v1-product-marketplace-products.universal-By2yn-nV.d.ts | AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/es/suppliershub-marketplace-v1-product-marketplace-products.universal-By2yn-nV.d.mts | AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated code. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Wix auto-SDK packages consistently omit descriptions; stable false positive for this publisher. | ai | |
| provenance | no-provenance | AI (provenance): Wix CI pipeline does not attach Sigstore provenance; consistent across all approved Wix SDK packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Wix auto-generated SDK package; templated name, no description/repo are expected for this publisher's pipeline. | ai |
Versions (showing 38 of 38)
| Version | Deps | Published |
|---|---|---|
| 1.0.37 | 3 / 2 | |
| 1.0.36 | 3 / 2 | |
| 1.0.35 | 3 / 2 | |
| 1.0.34 | 2 / 2 | |
| 1.0.33 | 2 / 2 | |
| 1.0.32 | 2 / 2 | |
| 1.0.31 | 2 / 2 | |
| 1.0.30 | 2 / 2 | |
| 1.0.29 | 2 / 2 | |
| 1.0.28 | 2 / 2 | |
| 1.0.27 | 2 / 2 | |
| 1.0.26 | 2 / 2 | |
| 1.0.25 | 2 / 2 | |
| 1.0.24 | 2 / 2 | |
| 1.0.23 | 2 / 2 | |
| 1.0.22 | 2 / 2 | |
| 1.0.21 | 2 / 2 | |
| 1.0.20 | 2 / 2 | |
| 1.0.19 | 2 / 2 | |
| 1.0.18 | 2 / 2 | |
| 1.0.17 | 2 / 2 | |
| 1.0.16 | 2 / 2 | |
| 1.0.15 | 2 / 2 | |
| 1.0.14 | 2 / 2 | |
| 1.0.13 | 2 / 2 | |
| 1.0.12 | 2 / 2 | |
| 1.0.11 | 2 / 2 | |
| 1.0.10 | 2 / 2 | |
| 1.0.9 | 2 / 2 | |
| 1.0.8 | 2 / 2 | |
| 1.0.7 | 2 / 2 | |
| 1.0.6 | 2 / 2 | |
| 1.0.5 | 2 / 2 | |
| 1.0.4 | 2 / 2 | |
| 1.0.3 | 2 / 2 | |
| 1.0.2 | 2 / 2 | |
| 1.0.1 | 2 / 2 | |
| 1.0.0 | 2 / 2 |
v1.0.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.34
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.33
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.32
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.31
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.17
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.16
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.15
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.14
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.13
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.