tscircuit
Make electronics using Typescript, React, and AI tools.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/react-reconciler | AI (phantom-deps): Framework-scoped type package; conventionally loaded with react-reconciler, not a real missing import. | ai | |
| phantom-deps | phantom-dep:jscad-fiber | AI (phantom-deps): Aggregator package re-exports many subpackages; not imported directly by design. | ai | |
| phantom-deps | phantom-dep:@tscircuit/schematic-corpus | AI (phantom-deps): Aggregator package re-exports many subpackages; not imported directly by design. | ai | |
| phantom-deps | phantom-dep:@babel/standalone | AI (phantom-deps): Framework-scoped dep loaded by convention, not a risk. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs local build script + ignore-scripts install; no external fetch, consistent across releases. | ai | |
| phantom-deps | phantom-dep:@tscircuit/circuit-json-flex | AI (phantom-deps): Bundled build output; used indirectly, consistent with other accepted phantom deps. | ai | |
| phantom-deps | phantom-dep:@tscircuit/pcb-viewer | AI (phantom-deps): Meta-package re-exports sibling deps; not a real risk. | ai | |
| phantom-deps | phantom-dep:@tscircuit/react-fiber | AI (phantom-deps): Meta-package re-exports sibling deps; not a real risk. | ai | |
| phantom-deps | phantom-dep:@tscircuit/schematic-viewer | AI (phantom-deps): Meta-package re-exports sibling deps; not a real risk. | ai | |
| phantom-deps | phantom-dep:circuit-json-to-pnp-csv | AI (phantom-deps): Package ships only pre-bundled minified dist; no scannable imports. Dep is seveibar-maintained, on-function (PnP CSV), no install scripts. | ai | |
| phantom-deps | phantom-dep:@tscircuit/internal-dynamic-import | AI (phantom-deps): Same-org dep (seveibar), no install scripts. Phantom flag is an artifact of bundled-only dist with no import text. | ai | |
| phantom-deps | phantom-dep:@tscircuit/infer-cable-insertion-point | AI (phantom-deps): First-party @tscircuit scoped dep; phantom flag caused by bundled-only dist output, stable across versions. | ai | |
| phantom-deps | phantom-dep:@tscircuit/solver-utils | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/image-utils | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:kicad-to-circuit-json | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:circuit-json-to-spice | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:circuit-json-to-gltf | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/matchpack | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/miniflex | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:circuit-json-to-bpc | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:connectivity-map | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@flatten-js/core | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/schematic-trace-solver | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:circuit-json-to-connectivity-map | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/schematic-match-adapt | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/ngspice-spice-engine | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/copper-pour-solver | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:kicad-component-converter | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:circuit-json-to-simple-3d | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:calculate-cell-boundaries | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:@tscircuit/simple-3d-svg | AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. | ai | |
| phantom-deps | phantom-dep:calculate-elbow | AI (phantom-deps): Re-exported meta-package dep, not directly imported by design. | ai | |
| dependencies | unvetted-dep:@tscircuit/schematic-corpus | AI (dependencies): First-party tscircuit org package, part of same monorepo family. | ai | |
| phantom-deps | phantom-dep:@tscircuit/create-fdm-enclosure | AI (phantom-deps): Official tscircuit scoped package, likely used indirectly via build/runtime wiring. | ai | |
| dependencies | unvetted-dep:@tscircuit/create-fdm-enclosure | AI (dependencies): First-party tscircuit org package, consistent with monorepo ecosystem. | ai | |
| phantom-deps | phantom-dep:@resvg/resvg-js | AI (phantom-deps): Bundled ecosystem dep, config-referenced not directly imported; stable false positive. | ai | |
| phantom-deps | phantom-dep:jscad-planner | AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. | ai | |
| phantom-deps | phantom-dep:minicssgrid | AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. | ai | |
| phantom-deps | phantom-dep:s-expression | AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. | ai | |
| phantom-deps | phantom-dep:graphics-debug | AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. | ai | |
| phantom-deps | phantom-dep:circuit-to-svg | AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. | ai | |
| dependencies | unvetted-dep:@tscircuit/react-fiber | AI (dependencies): First-party @tscircuit org dependency, same maintainer/ecosystem. | ai | |
| phantom-deps | phantom-dep:@tscircuit/schematic-autolayout | AI (phantom-deps): Used via config/type references, not direct import; benign for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@tscircuit/props | AI (phantom-deps): Used via config/type references, not direct import; benign for this monorepo package. | ai | |
| dependencies | unvetted-dep:@tscircuit/builder | AI (dependencies): First-party @tscircuit org dependency, same maintainer/ecosystem. | ai | |
| phantom-deps | phantom-dep:kicadts | AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. | ai | |
| phantom-deps | phantom-dep:manifold-3d | AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. | ai | |
| phantom-deps | phantom-dep:@lume/kiwi | AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. | ai | |
| phantom-deps | phantom-dep:bpc-graph | AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. | ai | |
| phantom-deps | phantom-dep:spicets | AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. | ai | |
| phantom-deps | phantom-dep:poppygl | AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. | ai | |
| phantom-deps | phantom-dep:spicey | AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. | ai | |
| source-diff | net-exec-file:dist/browser.min.js | AI (source-diff): Legitimate browser bundle exported via package.json exports map; code samples show React/module boilerplate, not malware. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects bundling of many deps into browser/webworker minified artifacts; expected for this package's architecture. | ai | |
| source-diff | net-exec-file:dist/webworker.min.js | AI (source-diff): Legitimate webworker bundle for tscircuit eval; consistent with documented build scripts and package structure. | ai | |
| phantom-deps | phantom-dep:@tscircuit/krt-wasm | AI (phantom-deps): Platform-specific binary package; legitimate implicit dependency for this monorepo. | ai | |
| source-diff | encoded-string-file:dist/webworker.min.js | AI (source-diff): Long string is SVG/CSS chart rendering code in a minified webworker bundle, not an obfuscated payload. | ai | |
| dependencies | unvetted-dep:@tscircuit/solver-utils | AI (dependencies): tscircuit first-party package; stable pattern across versions. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-commonjs | AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-node-resolve | AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-typescript | AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-json | AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. | ai | |
| phantom-deps | phantom-dep:@tscircuit/alphabet | AI (phantom-deps): Newly added tscircuit ecosystem dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:format-si-unit | AI (phantom-deps): Utility dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:css-select | AI (phantom-deps): Transitive dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer/bundled dep for browser build; stable false positive. | ai | |
| phantom-deps | phantom-dep:flatbush | AI (phantom-deps): Transitive spatial indexing dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:sucrase | AI (phantom-deps): Build-time dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:comlink | AI (phantom-deps): Used in web worker build; stable false positive. | ai | |
| phantom-deps | phantom-dep:rollup | AI (phantom-deps): Build tool referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): Known implicit TypeScript runtime dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): Stable false positive; debug is a transitive runtime dep in this large meta-package. | ai | |
| phantom-deps | phantom-dep:@tscircuit/infgrid-ijump-astar | AI (phantom-deps): tscircuit ecosystem dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tscircuit/circuit-json-util | AI (phantom-deps): tscircuit ecosystem dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tscircuit/checks | AI (phantom-deps): tscircuit ecosystem dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tscircuit/math-utils | AI (phantom-deps): tscircuit ecosystem dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tscircuit/runframe | AI (phantom-deps): tscircuit ecosystem dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tscircuit/soup-util | AI (phantom-deps): tscircuit ecosystem dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:transformation-matrix | AI (phantom-deps): Math utility dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:svg-path-commander | AI (phantom-deps): SVG utility dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-dts | AI (phantom-deps): Build tool; stable false positive. | ai | |
| phantom-deps | phantom-dep:calculate-packing | AI (phantom-deps): Geometry dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:performance-now | AI (phantom-deps): Polyfill dep; stable false positive. | ai | |
| dependencies | unvetted-dep:@tscircuit/miniflex | AI (dependencies): tscircuit first-party dep; stable. | ai | |
| dependencies | unvetted-dep:@tscircuit/footprinter | AI (dependencies): tscircuit first-party dep; stable. | ai | |
| dependencies | unvetted-dep:kicad-to-circuit-json | AI (dependencies): tscircuit ecosystem dep; stable. | ai | |
| dependencies | unvetted-dep:circuit-json-to-spice | AI (dependencies): tscircuit ecosystem dep; stable. | ai | |
| dependencies | unvetted-dep:circuit-json-to-gltf | AI (dependencies): tscircuit ecosystem dep; stable. | ai | |
| dependencies | unvetted-dep:@tscircuit/matchpack | AI (dependencies): tscircuit first-party dep; stable. | ai | |
| dependencies | unvetted-dep:circuit-json-to-bpc | AI (dependencies): tscircuit ecosystem dep; stable. | ai | |
| dependencies | unvetted-dep:spicey | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@tscircuit/alphabet | AI (dependencies): tscircuit first-party dep; stable. | ai | |
| dependencies | unvetted-dep:connectivity-map | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:calculate-elbow | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@resvg/resvg-js | AI (dependencies): Well-known SVG rendering library; stable for this package. | ai | |
| dependencies | unvetted-dep:graphics-debug | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:circuit-to-svg | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:jscad-planner | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:s-expression | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:minicssgrid | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:bpc-graph | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:poppygl | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:kicadts | AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. | ai | |
| source-diff | encoded-string-file:dist/browser.min.js | AI (source-diff): tscircuit ships a minified browser bundle; long strings in dist/browser.min.js are CSS-in-JS and UI code, not malicious payloads. This is stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): svg-path-commander is a legitimate SVG utility; @tscircuit/alphabet is a first-party tscircuit package. Both additions are benign for this EDA library. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Bundled meta-package pattern; react is a legitimate peer/bundled dependency for this EDA toolkit. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): tscircuit is a bundled meta-package; phantom deps are expected false positives from the tsup build pattern where deps are bundled rather than directly imported. | ai | |
| phantom-deps | phantom-dep:schematic-symbols | AI (phantom-deps): Bundled meta-package pattern; legitimate tscircuit ecosystem dependency. | ai | |
| phantom-deps | phantom-dep:circuit-json | AI (phantom-deps): Bundled meta-package pattern; all @tscircuit ecosystem deps are expected to appear as phantom deps in this umbrella package. | ai | |
| phantom-deps | phantom-dep:@tscircuit/footprinter | AI (phantom-deps): Bundled meta-package pattern; legitimate tscircuit scoped dependency. | ai | |
| phantom-deps | phantom-dep:@tscircuit/capacity-autorouter | AI (phantom-deps): Bundled meta-package pattern; legitimate tscircuit scoped dependency. | ai | |
| provenance | no-provenance | AI (provenance): tscircuit is a well-established package (1302 days, 2774 versions); lack of Sigstore provenance is not a security concern for this package. | ai |
Versions (showing 100 of 1841)
| Version | Deps | Published |
|---|---|---|
| 0.0.1727 | 67 / 4 | |
| 0.0.1726 | 67 / 4 | |
| 0.0.1725 | 67 / 4 | |
| 0.0.1724 | 67 / 4 | |
| 0.0.1723 | 67 / 4 | |
| 0.0.1722 | 67 / 4 | |
| 0.0.1721 | 67 / 4 | |
| 0.0.1720 | 67 / 4 | |
| 0.0.1719 | 67 / 4 | |
| 0.0.1718 | 67 / 4 | |
| 0.0.1717 | 67 / 4 | |
| 0.0.1716 | 67 / 4 | |
| 0.0.1715 | 67 / 4 | |
| 0.0.1714 | 67 / 4 | |
| 0.0.1713 | 67 / 4 | |
| 0.0.1712 | 67 / 4 | |
| 0.0.1711 | 67 / 4 | |
| 0.0.1710 | 67 / 4 | |
| 0.0.1709 | 67 / 4 | |
| 0.0.1708 | 67 / 4 | |
| 0.0.1707 | 67 / 4 | |
| 0.0.1706 | 67 / 4 | |
| 0.0.1705 | 67 / 4 | |
| 0.0.1704 | 67 / 4 | |
| 0.0.1703 | 67 / 4 | |
| 0.0.1702 | 67 / 4 | |
| 0.0.1701 | 66 / 4 | |
| 0.0.1700 | 66 / 4 | |
| 0.0.1699 | 66 / 4 | |
| 0.0.1698 | 66 / 4 | |
| 0.0.1697 | 66 / 4 | |
| 0.0.1696 | 66 / 4 | |
| 0.0.1695 | 66 / 4 | |
| 0.0.1694 | 66 / 4 | |
| 0.0.1693 | 66 / 4 | |
| 0.0.1692 | 66 / 4 | |
| 0.0.1691 | 66 / 4 | |
| 0.0.1690 | 66 / 4 | |
| 0.0.1689 | 66 / 4 | |
| 0.0.1688 | 66 / 4 | |
| 0.0.1687 | 66 / 4 | |
| 0.0.1686 | 66 / 4 | |
| 0.0.1685 | 66 / 4 | |
| 0.0.1684 | 66 / 4 | |
| 0.0.1683 | 66 / 4 | |
| 0.0.1682 | 66 / 4 | |
| 0.0.1681 | 66 / 4 | |
| 0.0.1680 | 66 / 4 | |
| 0.0.1679 | 66 / 4 | |
| 0.0.1678 | 66 / 4 | |
| 0.0.1677 | 66 / 4 | |
| 0.0.1676 | 66 / 4 | |
| 0.0.1675 | 66 / 4 | |
| 0.0.1674 | 66 / 4 | |
| 0.0.1673 | 66 / 4 | |
| 0.0.1672 | 66 / 4 | |
| 0.0.1671 | 66 / 4 | |
| 0.0.1670 | 66 / 4 | |
| 0.0.1669 | 66 / 4 | |
| 0.0.1668 | 66 / 4 | |
| 0.0.1667 | 66 / 4 | |
| 0.0.1666 | 66 / 4 | |
| 0.0.1665 | 66 / 4 | |
| 0.0.1664 | 66 / 4 | |
| 0.0.1663 | 66 / 4 | |
| 0.0.1662 | 66 / 4 | |
| 0.0.1661 | 66 / 4 | |
| 0.0.1660 | 66 / 4 | |
| 0.0.1659 | 66 / 4 | |
| 0.0.1658 | 66 / 4 | |
| 0.0.1657 | 66 / 4 | |
| 0.0.1656 | 66 / 4 | |
| 0.0.1655 | 66 / 4 | |
| 0.0.1654 | 66 / 4 | |
| 0.0.1653 | 66 / 4 | |
| 0.0.1652 | 66 / 4 | |
| 0.0.1651 | 66 / 4 | |
| 0.0.1650 | 66 / 4 | |
| 0.0.1649 | 66 / 4 | |
| 0.0.1648 | 66 / 4 | |
| 0.0.1647 | 66 / 4 | |
| 0.0.1646 | 66 / 4 | |
| 0.0.1645 | 66 / 4 | |
| 0.0.1644 | 66 / 4 | |
| 0.0.1643 | 66 / 4 | |
| 0.0.1642 | 66 / 4 | |
| 0.0.1641 | 66 / 4 | |
| 0.0.1640 | 66 / 4 | |
| 0.0.1639 | 66 / 4 | |
| 0.0.1638 | 66 / 4 | |
| 0.0.1637 | 66 / 4 | |
| 0.0.1636 | 66 / 4 | |
| 0.0.1635 | 66 / 4 | |
| 0.0.1634 | 66 / 4 | |
| 0.0.1633 | 66 / 4 | |
| 0.0.1632 | 66 / 4 | |
| 0.0.1631 | 66 / 4 | |
| 0.0.1630 | 66 / 4 | |
| 0.0.1629 | 66 / 4 | |
| 0.0.1628 | 66 / 4 |
v0.0.1727
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1726
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1725
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1724
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1723
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1722
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1721
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1720
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1719
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1718
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1717
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1716
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1715
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1714
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1713
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1712
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1711
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1710
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1709
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1707
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1706
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1705
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1704
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1703
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1702
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1701
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1699
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1698
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1697
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1696
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1694
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1693
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1691
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1690
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1689
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1688
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1687
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1686
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1685
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1684
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1683
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1682
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1681
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1680
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1679
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1678
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1677
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1676
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1675
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1674
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1673
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1671
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1670
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1669
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1668
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1667
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1666
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1665
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1664
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1663
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1662
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1661
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1660
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1659
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1658
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1657
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1656
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1655
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1654
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1653
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1652
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1651
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1650
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1649
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1648
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1647
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1646
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1645
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1644
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1643
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1642
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1641
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1640
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1639
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1638
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1637
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1636
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1635
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1633
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1632
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1631
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1630
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1629
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1628
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.