slate-react
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file-transition:dist/slate-react.min.js | AI (source-diff): Minified build of same UMD bundle; no fetch/exec payload. | ai | |
| source-diff | net-exec-file-transition:dist/slate-react.js | AI (source-diff): Rollup UMD build output; heuristic net+exec match on bundle, no actual dropper behavior. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): slate-dev-warning is a first-party sibling package in the same monorepo. | ai | |
| phantom-deps | phantom-dep:keycode | AI (phantom-deps): Used in transpiled lib/ build output; heuristic misses it due to minification. | ai | |
| source-diff | bulk-obfuscated-files:lib | AI (source-diff): Routine transpiled build output under lib/, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:is-window | AI (phantom-deps): Legitimate small utility dep for DOM checks; likely used but not import-scannable. | ai | |
| phantom-deps | phantom-dep:tiny-invariant | AI (phantom-deps): Declared dependency; used transitively in slate-react codebase. | ai | |
| phantom-deps | phantom-dep:is-plain-object | AI (phantom-deps): Declared dependency; used transitively in slate-react codebase. | ai | |
| phantom-deps | phantom-dep:is-hotkey | AI (phantom-deps): Declared dependency; used transitively in slate-react codebase. | ai |
Versions (showing 100 of 290)
| Version | Deps | Published |
|---|---|---|
| 0.126.0 | 6 / 16 | |
| 0.125.1 | 6 / 16 | |
| 0.124.2 | 6 / 16 | |
| 0.124.0 | 6 / 16 | |
| 0.123.0 | 6 / 16 | |
| 0.120.0 | 6 / 16 | |
| 0.119.0 | 6 / 16 | |
| 0.118.2 | 6 / 16 | |
| 0.117.4 | 6 / 16 | |
| 0.117.3 | 6 / 16 | |
| 0.117.2 | 6 / 16 | |
| 0.117.1 | 6 / 16 | |
| 0.116.0 | 6 / 16 | |
| 0.115.0 | 6 / 15 | |
| 0.114.2 | 7 / 15 | |
| 0.114.0 | 7 / 15 | |
| 0.113.0 | 7 / 15 | |
| 0.112.1 | 7 / 15 | |
| 0.112.0 | 7 / 15 | |
| 0.111.0 | 7 / 15 | |
| 0.110.3 | 7 / 14 | |
| 0.110.2 | 7 / 14 | |
| 0.110.1 | 7 / 14 | |
| 0.110.0 | 7 / 14 | |
| 0.109.0 | 7 / 14 | |
| 0.108.0 | 7 / 14 | |
| 0.107.1 | 9 / 12 | |
| 0.107.0 | 9 / 12 | |
| 0.106.0 | 9 / 12 | |
| 0.105.0 | 9 / 12 | |
| 0.104.0 | 9 / 12 | |
| 0.102.0 | 9 / 12 | |
| 0.101.6 | 9 / 12 | |
| 0.101.5 | 9 / 12 | |
| 0.101.3 | 9 / 12 | |
| 0.101.2 | 9 / 12 | |
| 0.101.1 | 9 / 12 | |
| 0.101.0 | 9 / 12 | |
| 0.100.1 | 9 / 13 | |
| 0.100.0 | 9 / 13 | |
| 0.99.0 | 9 / 13 | |
| 0.98.4 | 9 / 13 | |
| 0.98.3 | 9 / 13 | |
| 0.98.2 | 9 / 13 | |
| 0.98.1 | 9 / 13 | |
| 0.98.0 | 9 / 13 | |
| 0.97.2 | 9 / 13 | |
| 0.97.1 | 9 / 13 | |
| 0.97.0 | 9 / 13 | |
| 0.96.0 | 9 / 13 | |
| 0.95.0 | 9 / 13 | |
| 0.94.2 | 9 / 13 | |
| 0.94.0 | 9 / 13 | |
| 0.93.0 | 9 / 13 | |
| 0.92.0 | 9 / 13 | |
| 0.91.11 | 9 / 13 | |
| 0.91.10 | 9 / 13 | |
| 0.91.9 | 9 / 13 | |
| 0.91.8 | 9 / 13 | |
| 0.91.7 | 9 / 13 | |
| 0.91.6 | 9 / 13 | |
| 0.91.5 | 9 / 13 | |
| 0.91.4 | 9 / 13 | |
| 0.91.3 | 9 / 13 | |
| 0.91.2 | 9 / 13 | |
| 0.91.1 | 9 / 13 | |
| 0.91.0 | 9 / 13 | |
| 0.90.0 | 9 / 13 | |
| 0.89.0 | 9 / 13 | |
| 0.88.2 | 8 / 13 | |
| 0.88.0 | 8 / 13 | |
| 0.87.1 | 8 / 13 | |
| 0.87.0 | 8 / 13 | |
| 0.86.0 | 8 / 12 | |
| 0.83.2 | 8 / 12 | |
| 0.83.1 | 8 / 12 | |
| 0.83.0 | 8 / 12 | |
| 0.76.0 | 8 / 12 | |
| 0.68.0 | 8 / 10 | |
| 0.61.3 | 7 / 3 | |
| 0.61.0 | 7 / 3 | |
| 0.60.17 | 7 / 3 | |
| 0.60.16 | 7 / 3 | |
| 0.60.15 | 7 / 3 | |
| 0.60.14 | 7 / 3 | |
| 0.60.11 | 7 / 3 | |
| 0.60.10 | 7 / 3 | |
| 0.60.9 | 7 / 3 | |
| 0.60.8 | 7 / 3 | |
| 0.60.4 | 7 / 3 | |
| 0.60.2 | 7 / 3 | |
| 0.60.1 | 7 / 3 | |
| 0.60.0 | 7 / 2 | |
| 0.58.4 | 7 / 2 | |
| 0.58.3 | 7 / 2 | |
| 0.58.2 | 7 / 2 | |
| 0.57.3 | 7 / 2 | |
| 0.57.2 | 7 / 2 | |
| 0.57.1 | 7 / 2 | |
| 0.57.0 | 7 / 2 |
v0.126.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.125.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.113.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.112.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.112.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.111.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.109.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.108.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.107.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.107.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.106.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.105.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.104.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.102.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.6
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.5
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.3
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.100.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.100.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.99.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.4
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.3
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.97.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.97.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.97.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.96.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.95.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.94.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.93.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.92.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.11
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.10
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.9
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.8
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.7
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.6
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.5
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.4
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.3
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.90.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.89.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.88.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.88.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.87.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.87.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.86.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.83.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.83.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.83.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.61.3
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-30. It has since remained available on npm for 1938 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.61.0
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-29. It has since remained available on npm for 1939 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.17
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-29. It has since remained available on npm for 1939 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.16
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-29. It has since remained available on npm for 1939 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.15
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-21. It has since remained available on npm for 1947 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.14
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-21. It has since remained available on npm for 1947 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.11
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-20. It has since remained available on npm for 1948 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.10
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-20. It has since remained available on npm for 1948 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.9
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-20. It has since remained available on npm for 1948 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.8
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-03-11. It has since remained available on npm for 1957 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.4
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-02-17. It has since remained available on npm for 1979 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.2
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2021-01-19. It has since remained available on npm for 2008 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.1
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2020-12-11. It has since remained available on npm for 2047 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.0
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (thesunny) than the most recent previously approved version (ianstormtaylor) on 2020-11-24. It has since remained available on npm for 2064 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.4
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (damareyoh) than the most recent previously approved version (ianstormtaylor) on 2020-07-08. It has since remained available on npm for 2204 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.3
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (damareyoh) than the most recent previously approved version (ianstormtaylor) on 2020-06-04. It has since remained available on npm for 2238 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.2
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (damareyoh) than the most recent previously approved version (ianstormtaylor) on 2020-05-27. It has since remained available on npm for 2245 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.3
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (damareyoh) than the most recent previously approved version (ianstormtaylor) on 2020-05-05. It has since remained available on npm for 2268 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.2
4 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (damareyoh) than the most recent previously approved version (ianstormtaylor) on 2020-04-24. It has since remained available on npm for 2278 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.