← Home

arkormx

Modern TypeScript-first ORM for Node.js.

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

3m1n3nc3

Keywords

ormdatabasetypescriptnodejssqlquery buildermigrationseedingmodelrepository

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/URLDriver-DoGM6Qgp.d.mts AI (source-diff): Same as above — bundler-generated .d.mts declaration file, not obfuscated. ai
source-diff obfuscated-file:dist/URLDriver-CXXyJrQ8.d.cts AI (source-diff): Bundler-generated TypeScript declaration file with long lines; not obfuscated, readable type definitions visible in sample. ai
source-diff obfuscated-file:dist/index-CEynlcyE.d.cts AI (source-diff): TypeScript declaration file with long lines from bundled type exports; not obfuscation. ai
source-diff obfuscated-file:dist/index-D_gtCoPF.d.mts AI (source-diff): TypeScript declaration file with long lines from bundled type exports; not obfuscation. ai
source-diff obfuscated-file:dist/index-DV9QDB5H.d.mts AI (source-diff): Same as above — bundled .d.mts declaration file, not obfuscated. ai
source-diff obfuscated-file:dist/relationship-k7kdsCor.mjs AI (source-diff): Minified ESM bundle from tsdown; sample shows readable class/import structure, no malicious patterns. ai
source-diff obfuscated-file:dist/index-XyE0Kf2W.d.cts AI (source-diff): Long-line TypeScript declaration file generated by tsdown bundler; not obfuscated code. ai
source-diff obfuscated-file:dist/index-zCAsfkq8.d.cts AI (source-diff): TypeScript declaration rollup with long type union lines; not obfuscated, standard tsdown output. ai
source-diff obfuscated-file:dist/index-C2Nfsd13.d.mts AI (source-diff): Same as above — ESM variant of the declaration rollup. ai
source-diff obfuscated-file:dist/index-CAb-D9th.d.mts AI (source-diff): Same as above — bundled type declarations with long lines, not obfuscated code. ai
source-diff obfuscated-file:dist/index-isqbM3Ch.d.cts AI (source-diff): Long lines in .d.cts are bundled TypeScript declarations, not obfuscation; stable pattern for this ORM package. ai
source-diff obfuscated-file:dist/relationship-AnKH8ZaV.mjs AI (source-diff): Minified ESM bundle output; sample shows readable ORM logic, consistent with tsdown build tooling. ai
source-diff obfuscated-file:dist/index-Bzrnhh8D.d.mts AI (source-diff): Same as above — bundled .d.mts declaration file with long lines, not obfuscated code. ai
source-diff obfuscated-file:dist/index-CvGo7r10.d.cts AI (source-diff): Long lines in .d.cts are bundled TypeScript declaration files, not obfuscation; stable pattern for this ORM package. ai
source-diff obfuscated-file:dist/relationship-RG9V2vgd.mjs AI (source-diff): Standard tsdown/vite bundle output; readable code with clear imports and class definitions, not obfuscated. ai
source-diff obfuscated-file:dist/index-BJDRQWuc.d.mts AI (source-diff): Standard bundler-generated type declaration file; long lines are concatenated type definitions, not obfuscation. ai
source-diff obfuscated-file:dist/index-D2xzn3OX.d.cts AI (source-diff): Standard bundler-generated type declaration file; long lines are concatenated type definitions, not obfuscation. ai
source-diff obfuscated-file:dist/index-DbtnN_Yb.d.mts AI (source-diff): Same pattern: bundled .d.mts type declaration file, not obfuscated. ai
source-diff obfuscated-file:dist/index-nSC0udqX.d.cts AI (source-diff): Long-line TypeScript declaration file from bundler output; not obfuscated, just minified type defs. ai
source-diff obfuscated-file:dist/relationship-CJaPnw92.mjs AI (source-diff): Bundled ESM output with readable code; long lines from bundler, not obfuscation. ai
source-diff obfuscated-file:dist/index-BD0RC4Si.d.cts AI (source-diff): TypeScript declaration rollup with long type union lines; standard tsdown bundler output, not obfuscation. ai
source-diff obfuscated-file:dist/relationship-DcvK5Xn-.mjs AI (source-diff): Readable ORM source bundled by tsdown; long lines from bundler concatenation, not obfuscation. ai
source-diff obfuscated-file:dist/index-Wg5flH28.d.mts AI (source-diff): Same as above — ESM variant of the declaration rollup. ai
source-diff obfuscated-file:dist/URLDriver-BpGqakSw.d.cts AI (source-diff): Bundler-generated type declaration file; long lines are concatenated TS interfaces, not obfuscation. ai
source-diff obfuscated-file:dist/MorphToManyRelation-DWmrAkT8.mjs AI (source-diff): Minified ORM bundle output from tsdown; sample shows readable ORM class definitions, no malicious patterns. ai
source-diff obfuscated-file:dist/URLDriver-DMJkuKOm.d.mts AI (source-diff): Same as above — bundler-generated .d.mts type declaration, not obfuscated code. ai
phantom-deps phantom-dep:pg AI (phantom-deps): pg is a declared runtime dep used via Kysely/Prisma adapter; phantom-dep heuristic false positive. ai
source-diff obfuscated-file:dist/MorphToManyRelation-B2rHb9hS.mjs AI (source-diff): Minified/bundled ESM chunk from tsdown; sample shows standard ORM relation code. ai
source-diff obfuscated-file:dist/URLDriver-DxufCVQn.d.mts AI (source-diff): Same pattern — bundled .d.mts declaration file, readable ORM type definitions. ai
source-diff obfuscated-file:dist/URLDriver-LfQB9POc.d.cts AI (source-diff): Long-line bundled TypeScript declaration file from tsdown build; not obfuscated. ai
phantom-deps phantom-dep:@viteplus/versions AI (phantom-deps): Referenced in config/build tooling; stable false positive for this package. ai
source-diff obfuscated-file:dist/index-RvyusnXP.d.mts AI (source-diff): Same as above — bundler-generated .d.mts declaration file, not obfuscated. ai
source-diff obfuscated-file:dist/index-BQyFSgj_.d.cts AI (source-diff): Standard tsdown/rollup bundle output with hash suffix; content is readable TypeScript type declarations. ai
source-diff obfuscated-file:dist/relationship-BBMs-1iK.mjs AI (source-diff): Minified ESM bundle from tsdown; content is readable ORM relationship logic, no malicious patterns. ai
phantom-deps phantom-dep:@h3ravel/support AI (phantom-deps): Declared dependency used indirectly through ORM support libraries; stable false positive. ai
phantom-deps phantom-dep:@h3ravel/shared AI (phantom-deps): Declared dependency used indirectly through ORM support libraries; stable false positive. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): dotenv is a declared dependency used for environment configuration; stable false positive. ai

Versions (showing 51 of 57)

View all versions
Version Deps Published
2.4.1 8 / 24
2.4.0 8 / 24
2.3.1 8 / 24
2.3.0 8 / 24
2.2.3 8 / 24
2.2.2 8 / 24
2.2.1 8 / 24
2.2.0 8 / 24
2.1.1 8 / 24
2.1.0 8 / 24
2.0.11 8 / 24
2.0.10 8 / 24
2.0.9 9 / 16
2.0.8 9 / 16
2.0.7 9 / 18
2.0.6 9 / 18
2.0.5 9 / 18
2.0.4 9 / 17
2.0.3 9 / 17
2.0.2 9 / 17
2.0.1 9 / 17
2.0.0 9 / 17
1.3.5 6 / 17
1.3.4 6 / 17
1.3.3 6 / 17
1.3.2 6 / 17
1.3.1 5 / 17
1.3.0 5 / 17
1.2.2 5 / 17
1.2.1 5 / 17
1.2.0 5 / 17
1.1.0 5 / 17
1.0.0 5 / 17
0.2.11 5 / 17
0.2.10 5 / 17
0.2.9 5 / 17
0.2.8 5 / 17
0.2.7 5 / 17
0.2.6 5 / 17
0.2.5 5 / 17
0.2.4 5 / 17
0.2.3 5 / 17
0.2.2 5 / 17
0.2.1 5 / 17
0.2.0 5 / 17
0.1.11 5 / 17
0.1.10 6 / 17
0.1.9 6 / 17
0.1.8 6 / 17
0.1.7 6 / 17
0.1.6 6 / 17

v2.4.1

4 findings
HIGH New obfuscated file: dist/index-BD0RC4Si.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-DcvK5Xn-.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Wg5flH28.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

4 findings
HIGH New obfuscated file: dist/index-BD0RC4Si.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-DcvK5Xn-.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Wg5flH28.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.1

4 findings
HIGH New obfuscated file: dist/index-XyE0Kf2W.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-k7kdsCor.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DV9QDB5H.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

4 findings
HIGH New obfuscated file: dist/index-nSC0udqX.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-CJaPnw92.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DbtnN_Yb.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.3

4 findings
HIGH New obfuscated file: dist/index-nSC0udqX.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-CJaPnw92.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DbtnN_Yb.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.2

4 findings
HIGH New obfuscated file: dist/index-zCAsfkq8.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-CJaPnw92.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C2Nfsd13.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.1

4 findings
HIGH New obfuscated file: dist/index-CEynlcyE.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-AnKH8ZaV.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-D_gtCoPF.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

4 findings
HIGH New obfuscated file: dist/index-isqbM3Ch.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-AnKH8ZaV.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CAb-D9th.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.1

4 findings
HIGH New obfuscated file: dist/index-BQyFSgj_.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-BBMs-1iK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-RvyusnXP.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

4 findings
HIGH New obfuscated file: dist/index-BQyFSgj_.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-BBMs-1iK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-RvyusnXP.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

4 findings
HIGH New obfuscated file: dist/index-D2xzn3OX.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-RG9V2vgd.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BJDRQWuc.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.10

4 findings
HIGH New obfuscated file: dist/index-CvGo7r10.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/relationship-RG9V2vgd.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bzrnhh8D.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.9

4 findings
HIGH New obfuscated file: dist/URLDriver-BpGqakSw.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/MorphToManyRelation-DWmrAkT8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/URLDriver-DMJkuKOm.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.8

4 findings
HIGH New obfuscated file: dist/URLDriver-CXXyJrQ8.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/MorphToManyRelation-DWmrAkT8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/URLDriver-DoGM6Qgp.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.7

4 findings
HIGH New obfuscated file: dist/URLDriver-LfQB9POc.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/MorphToManyRelation-B2rHb9hS.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/URLDriver-DxufCVQn.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.