bpmn-js-element-templates
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/index.mjs | AI (source-diff): Legitimate ESM entry with normal package imports. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Diff baseline is 2+ years old; size growth reflects legitimate feature accumulation. | ai | |
| source-diff | net-exec-file:dist/bpmn-js-element-templates.umd.js | AI (source-diff): Standard rollup UMD bundle output, not a dropper. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): semver is a well-known, widely-used utility dependency. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer is a known bpmn-io contributor, part of normal team rotation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Routine maintainer rotation within bpmn-io org, no takeover behavior. | ai | |
| phantom-deps | phantom-dep:preact-markup | AI (phantom-deps): Used via config/templating, not a real phantom dep concern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Legit long-running bpmn-io package; spam signal is stale account-history noise, not package behavior. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 2.28.0 | 11 / 51 | |
| 2.27.0 | 11 / 51 | |
| 2.26.0 | 11 / 51 | |
| 2.25.0 | 11 / 52 | |
| 2.24.0 | 11 / 52 | |
| 2.23.2 | 11 / 53 | |
| 2.23.1 | 11 / 53 | |
| 2.22.0 | 11 / 53 | |
| 2.19.0 | 11 / 53 | |
| 2.18.0 | 11 / 54 | |
| 2.17.0 | 11 / 54 | |
| 2.16.1 | 11 / 54 | |
| 2.16.0 | 11 / 54 | |
| 2.15.1 | 11 / 54 | |
| 2.14.0 | 11 / 54 | |
| 2.13.0 | 11 / 54 | |
| 2.10.0 | 11 / 54 | |
| 2.6.0 | 11 / 54 | |
| 2.5.3 | 11 / 54 | |
| 2.4.0 | 11 / 54 | |
| 2.3.0 | 10 / 52 | |
| 2.2.1 | 10 / 52 | |
| 2.2.0 | 10 / 52 | |
| 2.0.0 | 10 / 52 |
v2.28.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (alekseymanetov) on 2026-07-27, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.27.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (jarekdanielak) on 2026-06-29, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.26.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (nikku) on 2026-06-19, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.25.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (alekseymanetov) on 2026-06-03, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.23.2
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): SPAM-FLAGGED maintainer signal applies to all versions published by this account.) Matched 1 signal(s), weighted score 3: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: bpmn-io-admin, barinali, jarekdanielak.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (barmac) on 2026-02-05, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.18.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (nikku) on 2025-12-18, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.17.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (nikku) on 2025-12-08, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.16.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (simon-steinruecken-camunda) than the most recent previously approved version (barmac) on 2025-11-21, but simon-steinruecken-camunda is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.16.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (nikku) on 2025-11-21, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.15.1
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (barmac) than the most recent previously approved version (nikku) on 2025-11-17, but barmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.14.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (jarekdanielak) on 2025-09-18, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.13.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikku) than the most recent previously approved version (simon-steinruecken-camunda) on 2025-09-18, but nikku is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.10.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (simon-steinruecken-camunda) than the most recent previously approved version (jarekdanielak) on 2025-08-14, but simon-steinruecken-camunda is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (nikku) on 2025-02-11, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.4.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jarekdanielak) than the most recent previously approved version (nikku) on 2024-12-12, but jarekdanielak is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.