@xyo-network/chain-sdk
XYO Layer One SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost ganache RPC in e2e test spec, not a real remote raw-IP endpoint. | ai | |
| phantom-deps | phantom-dep:@xyo-network/account-model | AI (phantom-deps): Same-org sibling package, likely type-only or re-export usage. | ai | |
| phantom-deps | phantom-dep:@xyo-network/wallet-model | AI (phantom-deps): Same-org sibling package, likely type-only or re-export usage. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are standard OpenTelemetry/chalk packages, consistent with added telemetry features. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff spans many skipped npm versions consolidating sibling packages, not a sudden bundle injection. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth explained by merged chain-* submodules across skipped versions. | ai | |
| provenance | no-provenance | AI (provenance): Established xyo-network publisher; lack of provenance is consistent across their package ecosystem. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-rpc | AI (dependencies): Same-org monorepo sibling package, pinned to matching version; not an independent risk. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-viewers | AI (dependencies): Same-org monorepo sibling package, pinned to matching version; not an independent risk. | ai |
Versions (showing 91 of 192)
| Version | Deps | Published |
|---|---|---|
| 1.7.14 | 18 / 17 | |
| 1.7.13 | 18 / 17 | |
| 1.7.12 | 18 / 17 | |
| 1.7.11 | 18 / 17 | |
| 1.7.10 | 18 / 17 | |
| 1.7.9 | 18 / 17 | |
| 1.7.8 | 18 / 17 | |
| 1.7.7 | 18 / 17 | |
| 1.7.6 | 18 / 17 | |
| 1.7.5 | 18 / 17 | |
| 1.7.4 | 18 / 17 | |
| 1.7.3 | 18 / 17 | |
| 1.7.2 | 18 / 17 | |
| 1.7.1 | 18 / 17 | |
| 1.7.0 | 18 / 17 | |
| 1.6.6 | 18 / 17 | |
| 1.6.5 | 18 / 17 | |
| 1.6.4 | 18 / 17 | |
| 1.6.3 | 18 / 17 | |
| 1.6.2 | 18 / 17 | |
| 1.6.1 | 18 / 17 | |
| 1.6.0 | 18 / 17 | |
| 1.5.37 | 18 / 17 | |
| 1.5.36 | 18 / 17 | |
| 1.5.35 | 18 / 17 | |
| 1.5.34 | 18 / 17 | |
| 1.5.33 | 18 / 17 | |
| 1.5.32 | 18 / 17 | |
| 1.5.31 | 18 / 17 | |
| 1.5.30 | 18 / 17 | |
| 1.5.29 | 18 / 17 | |
| 1.5.28 | 18 / 17 | |
| 1.5.27 | 18 / 17 | |
| 1.5.26 | 18 / 17 | |
| 1.5.25 | 18 / 17 | |
| 1.5.24 | 18 / 17 | |
| 1.5.23 | 18 / 17 | |
| 1.5.22 | 18 / 17 | |
| 1.5.21 | 18 / 17 | |
| 1.5.20 | 18 / 17 | |
| 1.5.19 | 18 / 17 | |
| 1.5.18 | 18 / 17 | |
| 1.5.17 | 18 / 17 | |
| 1.5.16 | 18 / 17 | |
| 1.5.15 | 18 / 17 | |
| 1.5.14 | 18 / 17 | |
| 1.5.13 | 18 / 17 | |
| 1.5.12 | 18 / 17 | |
| 1.5.11 | 18 / 17 | |
| 1.5.10 | 18 / 17 | |
| 1.5.9 | 18 / 17 | |
| 1.5.8 | 18 / 17 | |
| 1.5.7 | 18 / 17 | |
| 1.5.6 | 18 / 17 | |
| 1.5.5 | 18 / 17 | |
| 1.5.4 | 18 / 17 | |
| 1.5.3 | 18 / 17 | |
| 1.5.2 | 18 / 17 | |
| 1.5.1 | 18 / 17 | |
| 1.5.0 | 18 / 17 | |
| 1.4.8 | 18 / 17 | |
| 1.4.7 | 18 / 17 | |
| 1.4.6 | 18 / 17 | |
| 1.4.5 | 18 / 17 | |
| 1.4.4 | 18 / 17 | |
| 1.4.3 | 18 / 17 | |
| 1.4.2 | 18 / 17 | |
| 1.4.0 | 18 / 17 | |
| 1.3.31 | 18 / 17 | |
| 1.3.30 | 18 / 17 | |
| 1.3.29 | 18 / 17 | |
| 1.3.28 | 18 / 17 | |
| 1.3.27 | 19 / 15 | |
| 1.3.26 | 19 / 15 | |
| 1.3.25 | 19 / 15 | |
| 1.3.24 | 19 / 15 | |
| 1.3.23 | 19 / 15 | |
| 1.3.22 | 19 / 15 | |
| 1.3.21 | 19 / 15 | |
| 1.3.20 | 19 / 15 | |
| 1.3.19 | 19 / 15 | |
| 1.3.18 | 19 / 15 | |
| 1.3.17 | 19 / 15 | |
| 1.3.16 | 19 / 15 | |
| 1.3.15 | 19 / 15 | |
| 1.3.14 | 19 / 15 | |
| 1.3.13 | 19 / 15 | |
| 1.3.12 | 19 / 15 | |
| 1.3.11 | 20 / 15 | |
| 1.3.10 | 20 / 14 | |
| 1.3.9 | 20 / 14 |
v1.7.14
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f2470f9673d293b7fa162ec9719907851d7d6a4f/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f2470f9673d293b7fa162ec9719907851d7d6a4f/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f2470f9673d293b7fa162ec9719907851d7d6a4f/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f2470f9673d293b7fa162ec9719907851d7d6a4f/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-23, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.13
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b2da78e235964e748ea8ecf94f9eec6f16d3cd9b/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b2da78e235964e748ea8ecf94f9eec6f16d3cd9b/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b2da78e235964e748ea8ecf94f9eec6f16d3cd9b/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b2da78e235964e748ea8ecf94f9eec6f16d3cd9b/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-07-23, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.12
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e97d1defec95c2883888c77cd6d71a1319d2f1f7/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e97d1defec95c2883888c77cd6d71a1319d2f1f7/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e97d1defec95c2883888c77cd6d71a1319d2f1f7/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e97d1defec95c2883888c77cd6d71a1319d2f1f7/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-23, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.11
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8c25ca3783611e40dfd06cf1e5f231349ae70a60/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8c25ca3783611e40dfd06cf1e5f231349ae70a60/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8c25ca3783611e40dfd06cf1e5f231349ae70a60/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8c25ca3783611e40dfd06cf1e5f231349ae70a60/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-21, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.10
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6ce8949cd49f7f2c6b4870fb008d65740d11f7a8/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6ce8949cd49f7f2c6b4870fb008d65740d11f7a8/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6ce8949cd49f7f2c6b4870fb008d65740d11f7a8/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6ce8949cd49f7f2c6b4870fb008d65740d11f7a8/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.9
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/95f0a3963762dc9b9cef131aa628fba1c876d5a3/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/95f0a3963762dc9b9cef131aa628fba1c876d5a3/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/95f0a3963762dc9b9cef131aa628fba1c876d5a3/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/95f0a3963762dc9b9cef131aa628fba1c876d5a3/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-21, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.8
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-07-18, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-07-17, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-14, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-07-10, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-07-10, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-07-07, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-03, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.34
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-06-16, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.33
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-06-16, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.32
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-06-13, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.30
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-06-12, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.22
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-06-08, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.20
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-06-06, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.19
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-06-06, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-06-05, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.9
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-06-03, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-06-02, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-05-29, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.8
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-05-24, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (joelbcarter) on 2025-05-16, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.28
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (joelbcarter) on 2025-05-15, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.27
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (joelbcarter) on 2025-05-15, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.