projen
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| vendored-integrity | unresolved-vendored-tree:node_modules/@iarna/toml | AI (vendored-integrity): Declared bundledDependency; version-hash mismatch not implant evidence. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/undici-types | AI (vendored-integrity): Common @types/node transitive artifact, unchanged from prior approved version. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/just-diff-apply | AI (vendored-integrity): Transitive dep, unchanged from prior approved version. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/has-own-prop | AI (vendored-integrity): Transitive dep of bundled tooling; no diff vs prior approved version. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/yargs | AI (vendored-integrity): Bundled dependency declared in package.json; version mismatch only. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/xregexp | AI (vendored-integrity): Common transitive dep, unindexed version mismatch. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/which-module | AI (vendored-integrity): Common transitive dep, unindexed version mismatch. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/core-js-pure | AI (vendored-integrity): Transitive dep pulled via bundled deps; unindexed version, not an implant. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/ansi-regex | AI (vendored-integrity): Common transitive dep, unindexed version mismatch. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/@babel/runtime-corejs3 | AI (vendored-integrity): Transitive dep pulled via bundled deps; unindexed version, not an implant. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/yargs/node_modules/decamelize | AI (vendored-integrity): Nested transitive dep, unindexed version. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/y18n | AI (vendored-integrity): Common transitive dep, unindexed version mismatch. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/yargs-parser | AI (vendored-integrity): Nested transitive dep, unindexed version. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/@babel/runtime | AI (vendored-integrity): Common transitive toolchain dep; byte mismatch likely unindexed version, not implant. | ai | |
| vendored-integrity | unresolved-vendored-tree:node_modules/yaml | AI (vendored-integrity): yaml is a declared bundledDependency; expected vendoring, not a hidden payload. | ai | |
| source-diff | obfuscated-file:lib/util/task-env.js | AI (source-diff): Readable commented helper module; long-line heuristic false positive. | ai | |
| source-diff | obfuscated-file:lib/release/apply-version-bump.task.js | AI (source-diff): Readable commented CJS build output of release bump task; long-line heuristic false positive. | ai | |
| source-diff | obfuscated-file:lib/javascript/pnpm-workspace-config.js | AI (source-diff): jsii/json2jsii-generated schema serializer; long lines are codegen, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/util/exec.js | AI (source-diff): TSC-compiled ESM helpers, not obfuscation; stable build output. | ai | |
| source-diff | obfuscated-file:lib/task-shell.js | AI (source-diff): Compiled jsii class, legible source. | ai | |
| source-diff | obfuscated-file:lib/typescript/typescript-runner.js | AI (source-diff): Compiled jsii class, legible source. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in documented proxy-binding helper. | ai | |
| source-diff | obfuscated-file:lib/cli/cmds/synth.js | AI (source-diff): Standard tsc CJS output. | ai | |
| source-diff | encoded-string-file:lib/run-task.cjs | AI (source-diff): Bundled task runner (esbuild); long strings are build artifacts. | ai | |
| source-diff | obfuscated-file:lib/cli/cmds/run-task.js | AI (source-diff): TS-compiler emitted CJS; long lines are helper preamble, not obfuscation. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): getRealEnvVars in task runner; expected for a CLI. | ai | |
| source-diff | obfuscated-file:lib/task-runner.js | AI (source-diff): projen's own compiled task runner, tsc output not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cli/task-runtime.js | AI (source-diff): Compiled task runtime, tsc output. | ai | |
| source-diff | net-exec-file:node_modules/dax/script/mod.js | AI (source-diff): dax is a shell-execution library; network+exec patterns are its core functionality. | ai | |
| source-diff | obfuscated-file:node_modules/dax/esm/mod.js | AI (source-diff): Bundled transpiled output from dax (Deno-to-Node build); not obfuscated. | ai | |
| source-diff | obfuscated-file:node_modules/dax/script/mod.js | AI (source-diff): Bundled transpiled output from dax (Deno-to-Node build); not obfuscated. | ai | |
| source-diff | net-exec-file:node_modules/dax/esm/mod.js | AI (source-diff): dax is a shell-execution library; network+exec patterns are its core functionality. | ai | |
| source-diff | obfuscated-file:lib/cdk/jsii-build.js | AI (source-diff): jsii-compiled TS output with long lines; readable code, not obfuscation. Stable for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with SLSA provenance; legitimate CI/CD transition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): cdklabs-automation replaced by equivalent AWS automation accounts. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are known AWS/projen contributors. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): Legitimate AWS org transition: cdklabs-automation → mrgrain/amzn-oss/projen-automation. | ai | |
| source-diff | obfuscated-file:lib/python/pyproject-toml.js | AI (source-diff): jsii-compiled TypeScript; generated config types. | ai | |
| source-diff | obfuscated-file:lib/awscdk/private/feature-flags-v2.const.js | AI (source-diff): Generated CDK feature flags constant; long lines from large object literal. | ai | |
| source-diff | obfuscated-file:lib/util/diff.js | AI (source-diff): jsii-compiled TypeScript; readable diff utility. | ai | |
| source-diff | obfuscated-file:lib/github/dependency-review.js | AI (source-diff): jsii-compiled TypeScript; readable GitHub workflow component. | ai | |
| source-diff | obfuscated-file:lib/release/commit-tag-version.js | AI (source-diff): jsii-compiled TypeScript; readable release tooling. | ai | |
| source-diff | obfuscated-file:lib/release/bump-type.js | AI (source-diff): jsii-compiled TypeScript; readable semver utility functions. | ai | |
| source-diff | obfuscated-file:lib/javascript/biome/biome.js | AI (source-diff): jsii-compiled TypeScript class; readable source. | ai | |
| source-diff | obfuscated-file:lib/ai-instructions.js | AI (source-diff): jsii-compiled TypeScript, not obfuscated; readable source with JSDoc comments. | ai | |
| source-diff | obfuscated-file:lib/javascript/biome/biome-config.js | AI (source-diff): Generated config type definitions (toJson_ exports); long lines from many exports, not obfuscation. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Task runner intentionally merges process.env with task-specific env vars; core design of projen. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Plugin/module loader pattern; projen dynamically loads project modules by design. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI synth tool legitimately spawns child processes; expected for a project scaffolding tool. | ai | |
| phantom-deps | phantom-dep:shx | AI (phantom-deps): shx is listed in both dependencies and bundledDependencies; phantom-dep is a false positive here. | ai |
Versions (showing 100 of 222)
| Version | Deps | Published |
|---|---|---|
| 0.99.8 | 15 / 34 | |
| 0.99.7 | 15 / 34 | |
| 0.99.6 | 15 / 34 | |
| 0.99.5 | 15 / 34 | |
| 0.99.4 | 15 / 34 | |
| 0.99.3 | 15 / 34 | |
| 0.99.2 | 15 / 35 | |
| 0.99.1 | 15 / 34 | |
| 0.99.0 | 15 / 34 | |
| 0.98.34 | 15 / 34 | |
| 0.98.33 | 15 / 34 | |
| 0.98.32 | 15 / 34 | |
| 0.98.31 | 15 / 34 | |
| 0.98.30 | 15 / 34 | |
| 0.98.29 | 15 / 34 | |
| 0.98.28 | 15 / 34 | |
| 0.98.27 | 15 / 34 | |
| 0.98.26 | 15 / 34 | |
| 0.98.25 | 15 / 34 | |
| 0.98.24 | 15 / 34 | |
| 0.98.23 | 15 / 34 | |
| 0.98.22 | 15 / 34 | |
| 0.98.21 | 15 / 34 | |
| 0.98.20 | 15 / 34 | |
| 0.98.19 | 15 / 34 | |
| 0.98.18 | 15 / 34 | |
| 0.98.17 | 15 / 34 | |
| 0.98.16 | 15 / 34 | |
| 0.98.15 | 15 / 34 | |
| 0.98.14 | 15 / 34 | |
| 0.98.13 | 15 / 34 | |
| 0.98.12 | 15 / 34 | |
| 0.98.11 | 15 / 34 | |
| 0.98.10 | 15 / 34 | |
| 0.98.9 | 15 / 34 | |
| 0.98.8 | 15 / 34 | |
| 0.98.7 | 15 / 34 | |
| 0.91.20 | 14 / 30 | |
| 0.3.47 | 5 / 21 | |
| 0.3.46 | 5 / 21 | |
| 0.3.45 | 5 / 21 | |
| 0.3.43 | 5 / 21 | |
| 0.3.42 | 5 / 21 | |
| 0.3.41 | 5 / 21 | |
| 0.3.40 | 5 / 21 | |
| 0.3.39 | 5 / 21 | |
| 0.3.38 | 5 / 21 | |
| 0.3.37 | 5 / 21 | |
| 0.3.36 | 5 / 21 | |
| 0.3.35 | 5 / 21 | |
| 0.3.34 | 5 / 21 | |
| 0.3.33 | 5 / 21 | |
| 0.3.32 | 5 / 21 | |
| 0.3.31 | 5 / 21 | |
| 0.3.30 | 5 / 21 | |
| 0.3.29 | 4 / 20 | |
| 0.3.28 | 4 / 20 | |
| 0.3.27 | 4 / 20 | |
| 0.3.26 | 4 / 20 | |
| 0.3.25 | 4 / 20 | |
| 0.3.24 | 4 / 20 | |
| 0.3.23 | 4 / 20 | |
| 0.3.22 | 4 / 20 | |
| 0.3.21 | 4 / 20 | |
| 0.3.20 | 4 / 20 | |
| 0.3.19 | 4 / 20 | |
| 0.3.18 | 4 / 20 | |
| 0.3.17 | 4 / 20 | |
| 0.3.16 | 4 / 20 | |
| 0.3.15 | 4 / 20 | |
| 0.3.14 | 4 / 20 | |
| 0.3.13 | 5 / 21 | |
| 0.3.12 | 5 / 21 | |
| 0.3.11 | 5 / 21 | |
| 0.3.10 | 5 / 21 | |
| 0.3.8 | 5 / 21 | |
| 0.3.7 | 5 / 21 | |
| 0.3.6 | 5 / 21 | |
| 0.3.5 | 5 / 21 | |
| 0.3.4 | 5 / 21 | |
| 0.3.3 | 4 / 21 | |
| 0.3.2 | 4 / 21 | |
| 0.3.1 | 4 / 21 | |
| 0.3.0 | 4 / 21 | |
| 0.2.5 | 3 / 20 | |
| 0.2.4 | 3 / 20 | |
| 0.2.3 | 3 / 20 | |
| 0.2.2 | 3 / 20 | |
| 0.2.1 | 3 / 20 | |
| 0.2.0 | 3 / 20 | |
| 0.1.36 | 3 / 20 | |
| 0.1.35 | 3 / 20 | |
| 0.1.33 | 3 / 19 | |
| 0.1.32 | 3 / 19 | |
| 0.1.31 | 3 / 19 | |
| 0.1.30 | 3 / 19 | |
| 0.1.29 | 3 / 19 | |
| 0.1.28 | 2 / 18 | |
| 0.1.27 | 2 / 18 | |
| 0.1.26 | 2 / 18 |
v0.99.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.99.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.98.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.46
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.45
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.