← Home

@wovin/core

63
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tennoxgotjoshua

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/chunk-MPOFY7NX.min.js AI (source-diff): Minified esbuild bundle of mobx/typebox/browser-or-node; no malicious behavior. ai
provenance publisher-changed AI (provenance): Change reflects move to CI/CD publishing with SLSA provenance, an improvement. ai
dependencies unvetted-dep:iso-ucan AI (dependencies): Part of author's own iso-* UCAN toolkit, consistent with package purpose. ai
source-diff net-exec-file:dist/chunk-CZTDDXGE.min.js AI (source-diff): Bundled tsup build output; network+eval reflects normal IPFS/UCAN libs, no hostile destination. ai
publish-pattern new-deps-added AI (publish-pattern): hash-wasm is a legitimate hashing lib, consistent with package's crypto/IPFS functionality. ai
source-diff net-exec-file:dist/chunk-KEHU7HGZ.min.js AI (source-diff): Bundled mobx/tsup output, not a dropper; sample shows legit library source. ai
dependencies unvetted-dep:besonders-logger AI (dependencies): Pinned to exact version 1.0.2; package has SLSA provenance attestation reducing supply chain risk. ai
dependencies unvetted-dep:@oddjs/odd AI (dependencies): Established IPFS/FISSION ecosystem dep; package has SLSA provenance and long history. ai
source-diff large-new-source-files AI (source-diff): Large file growth matches legitimate feature expansion (IPNS/pubsub modules); SLSA provenance confirms build integrity. ai
source-diff net-exec-file:dist/chunk-CDYQMETJ.min.js AI (source-diff): Bundled chunk imports MobX, multiformats, crypto libs — standard build output, not malware. ai
bogus-package bogus-package AI (bogus-package): Established package with 97 versions and real download volume; missing metadata is a style choice, not a spam indicator. ai
npm-metadata no-description AI (npm-metadata): Consistent across all versions of this established package; not a malice signal. ai
phantom-deps phantom-dep:@libp2p/crypto AI (phantom-deps): Same bundled ESM pattern; stable false positive for this package. ai
phantom-deps phantom-dep:safe-stable-stringify AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for bundled/re-exported usage. ai
phantom-deps phantom-dep:besonders-logger AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for bundled/re-exported usage. ai
phantom-deps phantom-dep:@noble/hashes AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for bundled/re-exported usage. ai
phantom-deps phantom-dep:@oddjs/odd AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for bundled/re-exported usage. ai
phantom-deps phantom-dep:lodash-es AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for bundled/re-exported usage. ai
phantom-deps phantom-dep:hash-wasm AI (phantom-deps): Platform-specific binary; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:date-fns AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for bundled/re-exported usage. ai
phantom-deps phantom-dep:iso-kv AI (phantom-deps): Declared in dependencies; phantom-dep heuristic false positive for bundled/re-exported usage. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Declared in dependencies, likely used via re-exports or config; stable false positive for this package. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped package @wovin/core is unrelated to cors; Levenshtein match is a false positive for this established package. ai

Versions (showing 63 of 63)

Version Deps Published
0.3.6 18 / 8
0.3.5 18 / 8
0.3.4 18 / 8
0.3.3 18 / 8
0.3.2 18 / 8
0.3.0 18 / 8
0.2.2 16 / 8
0.1.36 18 / 7
0.1.35 18 / 7
0.1.34 18 / 7
0.1.33 18 / 7
0.1.32 18 / 7
0.1.31 18 / 7
0.1.30 18 / 7
0.1.29 18 / 7
0.1.28 18 / 7
0.1.27 18 / 7
0.1.26 16 / 7
0.1.25 16 / 7
0.1.24 16 / 7
0.1.23 16 / 7
0.1.22 16 / 7
0.1.21 16 / 7
0.1.20 16 / 7
0.1.19 16 / 7
0.1.18 16 / 7
0.1.17 16 / 7
0.1.15 12 / 7
0.1.13 12 / 7
0.1.11 12 / 7
0.1.9 12 / 7
0.1.8 12 / 7
0.1.7 12 / 7
0.1.6 12 / 7
0.1.5 12 / 7
0.1.4 12 / 7
0.1.3 12 / 7
0.1.2 12 / 7
0.1.1 12 / 7
0.1.0 12 / 7
0.0.26 12 / 7
0.0.25 12 / 7
0.0.24 12 / 7
0.0.23 12 / 7
0.0.21 12 / 7
0.0.20 12 / 7
0.0.19 12 / 7
0.0.18 12 / 7
0.0.17 12 / 7
0.0.16 12 / 7
0.0.15 12 / 7
0.0.14 11 / 7
0.0.13 11 / 7
0.0.12 11 / 7
0.0.11 11 / 7
0.0.10 11 / 7
0.0.8 9 / 7
0.0.7 9 / 7
0.0.6 10 / 7
0.0.5 10 / 7
0.0.4 10 / 7
0.0.2 11 / 7
0.0.1 0 / 2

v0.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

INFO Publisher changed: tennox → GitLab CI/CD (on 2026-02-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitLab CI/CD) than the most recent previously approved version (tennox) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.15

2 findings
HIGH New file with network + code execution: dist/chunk-KEHU7HGZ.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.