bpmn-js
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Active bpmn-io org package with 371 versions; dormancy flag is a false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established high-traffic bpmn.io package; small re-export index and org co-maintainers are benign, not spam. | ai | |
| dependencies | unvetted-dep:min-dash | AI (dependencies): Stable bpmn-io ecosystem dependency; used across all bpmn-js versions. | ai | |
| dependencies | unvetted-dep:tiny-svg | AI (dependencies): Stable bpmn-io ecosystem dependency; used across all bpmn-js versions. | ai | |
| dependencies | unvetted-dep:diagram-js | AI (dependencies): Core bpmn-io dependency; integral to bpmn-js across all versions. | ai | |
| dependencies | unvetted-dep:ids | AI (dependencies): Stable bpmn-io ecosystem dependency; used across all bpmn-js versions. | ai | |
| dependencies | unvetted-dep:inherits-browser | AI (dependencies): Stable bpmn-io ecosystem dependency; used across all bpmn-js versions. | ai | |
| dependencies | unvetted-dep:diagram-js-direct-editing | AI (dependencies): Stable bpmn-io ecosystem dependency; used across all bpmn-js versions. | ai | |
| dependencies | unvetted-dep:bpmn-moddle | AI (dependencies): Core bpmn-io dependency; integral to bpmn-js across all versions. | ai | |
| dependencies | unvetted-dep:min-dom | AI (dependencies): Stable bpmn-io ecosystem dependency; used across all bpmn-js versions. | ai |
Versions (showing 35 of 35)
| Version | Deps | Published |
|---|---|---|
| 18.22.0 | 8 / 44 | |
| 18.21.0 | 8 / 44 | |
| 18.20.0 | 8 / 44 | |
| 18.19.0 | 8 / 44 | |
| 18.18.0 | 8 / 44 | |
| 18.17.1 | 8 / 44 | |
| 18.17.0 | 8 / 44 | |
| 18.15.0 | 8 / 45 | |
| 18.14.0 | 8 / 45 | |
| 18.13.2 | 8 / 45 | |
| 18.13.1 | 8 / 45 | |
| 18.12.0 | 8 / 45 | |
| 18.11.0 | 8 / 45 | |
| 18.10.1 | 8 / 45 | |
| 18.10.0 | 8 / 45 | |
| 18.9.1 | 8 / 45 | |
| 18.9.0 | 8 / 45 | |
| 18.8.0 | 8 / 45 | |
| 18.7.0 | 8 / 45 | |
| 18.6.5 | 8 / 45 | |
| 18.6.4 | 8 / 45 | |
| 18.6.3 | 8 / 45 | |
| 18.6.2 | 8 / 45 | |
| 18.6.1 | 8 / 45 | |
| 18.6.0 | 8 / 45 | |
| 18.5.0 | 8 / 45 | |
| 18.4.0 | 8 / 45 | |
| 18.3.2 | 8 / 45 | |
| 18.3.1 | 8 / 45 | |
| 18.3.0 | 8 / 45 | |
| 18.2.0 | 8 / 45 | |
| 18.1.2 | 8 / 45 | |
| 18.1.1 | 8 / 45 | |
| 18.1.0 | 8 / 45 | |
| 18.0.0 | 8 / 45 |
v18.22.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alekseymanetov) than the most recent previously approved version (nikku) on 2026-07-23, but alekseymanetov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.20.0
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Spam-flagged maintainer added and effectively empty main entry point are disqualifying signals.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: bpmn-io-admin, barinali, jarekdanielak. • [S_EMPTY_MAIN] Entry point (lib/index.js) is 37 bytes — effectively empty.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.19.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (nikku) on 2026-06-24, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.17.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.14.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (alekseymanetov) on 2026-03-27, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.13.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.11.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (jarekdanielak) on 2026-02-02, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.10.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (jarekdanielak) on 2026-01-08, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.9.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (philippfromme) on 2025-11-18, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.8.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (barmac) on 2025-10-24, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.6.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (barmac) on 2025-09-19, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.6.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (jarekdanielak) on 2025-09-16, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.6.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (jarekdanielak) on 2025-08-19, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.6.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (philippfromme) on 2025-05-22, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.6.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (bpmn-io-admin) on 2025-04-25, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.6.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (bpmn-io-admin) on 2025-04-24, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.4.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bpmn-io-admin) than the most recent previously approved version (jarekdanielak) on 2025-03-19, but bpmn-io-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.3.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (philippfromme) on 2025-02-21, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bpmn-io-admin) than the most recent previously approved version (philippfromme) on 2025-02-18, but bpmn-io-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.2.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (philippfromme) than the most recent previously approved version (nikku) on 2025-01-24, but philippfromme is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v18.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.