@xyo-network/xl1-cli
XYO Layer One CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): Declared but not directly imported; framework-scoped usage consistent with this CLI package pattern. | ai | |
| phantom-deps | phantom-dep:msgpackr-extract | AI (phantom-deps): Peer/optional native dep for lmdb; not directly imported but legitimately declared for runtime use. | ai | |
| source-diff | encoded-string-file:dist/cli-min.mjs | AI (source-diff): Rollup-minified CLI bundle; long encoded strings are standard bundler output for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-metrics | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/host-metrics | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-trace-base | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/context-async-hooks | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-prometheus | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-http | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build tool and peer dependency; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-express | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-grpc | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-http | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-runtime-node | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/semantic-conventions | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/resources | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Config-referenced optional instrumentation; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:mongodb | AI (phantom-deps): Config-referenced optional storage backend; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:lmdb | AI (phantom-deps): Config-referenced optional storage backend; stable pattern for this package. | ai |
Versions (showing 100 of 127)
| Version | Deps | Published |
|---|---|---|
| 4.5.4 | 19 / 24 | |
| 4.5.3 | 19 / 22 | |
| 4.5.2 | 19 / 22 | |
| 4.5.1 | 19 / 22 | |
| 4.5.0 | 19 / 22 | |
| 4.4.0 | 19 / 22 | |
| 4.3.2 | 19 / 22 | |
| 4.3.1 | 19 / 23 | |
| 4.3.0 | 19 / 23 | |
| 4.2.1 | 19 / 23 | |
| 4.1.0 | 19 / 25 | |
| 4.0.6 | 19 / 37 | |
| 4.0.5 | 19 / 37 | |
| 4.0.4 | 19 / 67 | |
| 4.0.3 | 19 / 67 | |
| 4.0.2 | 19 / 66 | |
| 4.0.1 | 19 / 66 | |
| 4.0.0 | 19 / 93 | |
| 3.0.2 | 19 / 93 | |
| 3.0.1 | 19 / 93 | |
| 3.0.0 | 19 / 95 | |
| 2.0.18 | 19 / 93 | |
| 2.0.17 | 19 / 93 | |
| 2.0.16 | 19 / 93 | |
| 2.0.13 | 19 / 93 | |
| 2.0.9 | 18 / 112 | |
| 2.0.7 | 18 / 112 | |
| 2.0.5 | 18 / 112 | |
| 2.0.4 | 18 / 111 | |
| 2.0.3 | 18 / 111 | |
| 1.23.0 | 19 / 116 | |
| 1.22.0 | 20 / 120 | |
| 1.20.15 | 22 / 64 | |
| 1.20.14 | 22 / 64 | |
| 1.20.13 | 22 / 64 | |
| 1.20.12 | 22 / 64 | |
| 1.20.11 | 22 / 64 | |
| 1.20.10 | 22 / 63 | |
| 1.20.9 | 22 / 63 | |
| 1.20.8 | 21 / 65 | |
| 1.20.5 | 17 / 23 | |
| 1.20.4 | 17 / 23 | |
| 1.20.3 | 17 / 23 | |
| 1.20.2 | 17 / 23 | |
| 1.20.1 | 17 / 23 | |
| 1.20.0 | 17 / 23 | |
| 1.19.18 | 17 / 23 | |
| 1.19.17 | 17 / 25 | |
| 1.19.16 | 17 / 26 | |
| 1.19.15 | 16 / 29 | |
| 1.19.14 | 17 / 27 | |
| 1.19.13 | 17 / 27 | |
| 1.19.12 | 17 / 27 | |
| 1.19.11 | 17 / 27 | |
| 1.19.10 | 17 / 27 | |
| 1.19.9 | 17 / 27 | |
| 1.19.8 | 17 / 27 | |
| 1.19.7 | 17 / 27 | |
| 1.19.6 | 17 / 27 | |
| 1.19.5 | 17 / 28 | |
| 1.19.4 | 17 / 28 | |
| 1.19.3 | 17 / 28 | |
| 1.19.2 | 17 / 28 | |
| 1.19.1 | 17 / 28 | |
| 1.19.0 | 17 / 28 | |
| 1.18.5 | 17 / 28 | |
| 1.18.4 | 17 / 28 | |
| 1.18.2 | 17 / 28 | |
| 1.18.1 | 17 / 28 | |
| 1.18.0 | 17 / 28 | |
| 1.17.7 | 17 / 28 | |
| 1.17.6 | 17 / 28 | |
| 1.17.3 | 17 / 28 | |
| 1.17.2 | 17 / 28 | |
| 1.17.1 | 17 / 28 | |
| 1.17.0 | 17 / 28 | |
| 1.16.26 | 17 / 28 | |
| 1.16.25 | 17 / 28 | |
| 1.16.24 | 17 / 28 | |
| 1.16.23 | 17 / 28 | |
| 1.16.22 | 17 / 28 | |
| 1.16.21 | 17 / 28 | |
| 1.16.20 | 17 / 28 | |
| 1.16.19 | 17 / 28 | |
| 1.16.18 | 17 / 28 | |
| 1.16.17 | 17 / 28 | |
| 1.16.16 | 17 / 28 | |
| 1.16.15 | 17 / 28 | |
| 1.16.14 | 17 / 28 | |
| 1.16.13 | 17 / 28 | |
| 1.16.12 | 17 / 28 | |
| 1.16.11 | 17 / 28 | |
| 1.16.10 | 17 / 39 | |
| 1.16.9 | 17 / 39 | |
| 1.16.8 | 17 / 39 | |
| 1.16.7 | 17 / 39 | |
| 1.16.6 | 17 / 39 | |
| 1.16.5 | 17 / 39 | |
| 1.16.4 | 17 / 39 | |
| 1.16.3 | 17 / 39 |
v4.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-21, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.4.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-18, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-17, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-15, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-15, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-08, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-02, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2026-03-26, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.20.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2026-03-24, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.20.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2026-03-09, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.20.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2026-03-04, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.19.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2026-01-29, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.19.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (joelbcarter) on 2026-01-26, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.18.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (xyo) on 2026-01-15, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-12-12, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.17.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-12-11, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.17.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.25
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (joelbcarter) on 2025-11-23, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.24
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-11-21, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.23
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (joelbcarter) on 2025-11-19, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.21
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (xyo) on 2025-11-18, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-17, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-17, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.14
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-15, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-15, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-15, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-12, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-12, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-11, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.