← Home

playcademy

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

hbauereli-gooding

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Legitimate maintainer transition, new publisher has clean track record and inbound trust edges. ai
source-diff obfuscated-file:dist/runtime/game-runtime/index.js AI (source-diff): Bundled esbuild output with standard __esm/__export helpers, not obfuscation. ai
source-diff obfuscated-file:dist/runtime/dashboard-runtime/index.js AI (source-diff): Bundled esbuild output (hono/compose), not true obfuscation. ai
phantom-deps phantom-dep:json-colorizer AI (phantom-deps): Same as above — CLI tooling with bundled deps. ai
phantom-deps phantom-dep:colorette AI (phantom-deps): Same as above — CLI tooling with bundled deps. ai
phantom-deps phantom-dep:@hono/node-server AI (phantom-deps): Used indirectly via bundled CLI; stable false positive for this package. ai
phantom-deps phantom-dep:@inquirer/prompts AI (phantom-deps): CLI prompts dependency; bundled usage pattern triggers phantom-dep heuristic. ai
phantom-deps phantom-dep:@playcademy/utils AI (phantom-deps): Sibling monorepo package; indirect usage expected. ai
phantom-deps phantom-dep:@playcademy/edge-play AI (phantom-deps): Sibling monorepo package; indirect usage expected. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): CLI tool with config-file-driven deps; phantom-dep heuristic fires on bundled/indirect usage patterns. ai
phantom-deps phantom-dep:hono AI (phantom-deps): hono is a legitimate web framework; phantom detection is a false positive for this build-tool/CLI package that bundles deps via esbuild. ai
phantom-deps phantom-dep:commander AI (phantom-deps): commander is a legitimate declared dependency for CLI tooling; phantom detection likely reflects indirect usage not statically traced. ai
phantom-deps phantom-dep:dedent AI (phantom-deps): dedent is a legitimate declared dependency; phantom detection likely reflects indirect usage not statically traced. ai
phantom-deps phantom-dep:open AI (phantom-deps): open is a legitimate declared dependency; phantom detection likely reflects indirect usage in CLI code not statically traced. ai
dependencies unvetted-dep:miniflare AI (dependencies): Miniflare is Cloudflare's official local Workers simulator; its use is consistent with this package's Cloudflare Workers-based tooling purpose. ai

Versions (showing 51 of 151)

View all versions
Version Deps Published
0.28.0 16 / 23
0.27.0 16 / 22
0.23.0 16 / 22
0.22.1 16 / 22
0.22.0 16 / 22
0.21.0 16 / 22
0.20.0 16 / 22
0.19.8 16 / 22
0.19.7 16 / 22
0.19.6 16 / 22
0.19.5 16 / 22
0.19.4 16 / 22
0.19.3 16 / 22
0.19.2 16 / 22
0.19.1 16 / 22
0.19.0 16 / 22
0.18.9 16 / 20
0.18.8 16 / 21
0.18.7 16 / 21
0.18.6 16 / 21
0.18.5 16 / 21
0.18.4 16 / 21
0.18.3 16 / 21
0.18.2 16 / 21
0.18.1 16 / 21
0.18.0 16 / 21
0.17.5 16 / 21
0.17.4 16 / 13
0.17.3 16 / 13
0.17.2 16 / 13
0.17.1 16 / 11
0.17.0 16 / 11
0.16.17 16 / 11
0.16.16 16 / 11
0.16.15 16 / 11
0.16.14 16 / 11
0.16.13 16 / 11
0.16.12 16 / 11
0.16.11 16 / 11
0.16.10 16 / 11
0.16.9 16 / 11
0.16.8 16 / 11
0.16.7 16 / 11
0.16.6 16 / 11
0.16.5 16 / 11
0.16.4 16 / 11
0.16.3 16 / 11
0.16.2 16 / 11
0.16.1 16 / 11
0.16.0 16 / 11
0.15.6 16 / 11

v0.28.0

4 findings
HIGH Publisher changed: hbauer → eli-gooding (on unknown date) provenance

This version was published by a different npm account than previous versions on unknown date. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/runtime/dashboard-runtime/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/runtime/game-runtime/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.0

2 findings
HIGH Publisher changed: hbauer → eli-gooding (on 2026-07-12) provenance

This version was published by a different npm account than previous versions on 2026-07-12. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.