← Home

tscircuit

Make electronics using Typescript, React, and AI tools.

100
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

seveibar

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/react-reconciler AI (phantom-deps): Framework-scoped type package; conventionally loaded with react-reconciler, not a real missing import. ai
phantom-deps phantom-dep:jscad-fiber AI (phantom-deps): Aggregator package re-exports many subpackages; not imported directly by design. ai
phantom-deps phantom-dep:@tscircuit/schematic-corpus AI (phantom-deps): Aggregator package re-exports many subpackages; not imported directly by design. ai
phantom-deps phantom-dep:@babel/standalone AI (phantom-deps): Framework-scoped dep loaded by convention, not a risk. ai
install-scripts install-script:postinstall AI (install-scripts): Runs local build script + ignore-scripts install; no external fetch, consistent across releases. ai
phantom-deps phantom-dep:@tscircuit/circuit-json-flex AI (phantom-deps): Bundled build output; used indirectly, consistent with other accepted phantom deps. ai
phantom-deps phantom-dep:@tscircuit/pcb-viewer AI (phantom-deps): Meta-package re-exports sibling deps; not a real risk. ai
phantom-deps phantom-dep:@tscircuit/react-fiber AI (phantom-deps): Meta-package re-exports sibling deps; not a real risk. ai
phantom-deps phantom-dep:@tscircuit/schematic-viewer AI (phantom-deps): Meta-package re-exports sibling deps; not a real risk. ai
phantom-deps phantom-dep:circuit-json-to-pnp-csv AI (phantom-deps): Package ships only pre-bundled minified dist; no scannable imports. Dep is seveibar-maintained, on-function (PnP CSV), no install scripts. ai
phantom-deps phantom-dep:@tscircuit/internal-dynamic-import AI (phantom-deps): Same-org dep (seveibar), no install scripts. Phantom flag is an artifact of bundled-only dist with no import text. ai
phantom-deps phantom-dep:@tscircuit/infer-cable-insertion-point AI (phantom-deps): First-party @tscircuit scoped dep; phantom flag caused by bundled-only dist output, stable across versions. ai
phantom-deps phantom-dep:@tscircuit/solver-utils AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/image-utils AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:kicad-to-circuit-json AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:circuit-json-to-spice AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:circuit-json-to-gltf AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/matchpack AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/miniflex AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:circuit-json-to-bpc AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:connectivity-map AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@flatten-js/core AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/schematic-trace-solver AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:circuit-json-to-connectivity-map AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/schematic-match-adapt AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/ngspice-spice-engine AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/copper-pour-solver AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:kicad-component-converter AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:circuit-json-to-simple-3d AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:calculate-cell-boundaries AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:@tscircuit/simple-3d-svg AI (phantom-deps): Config-referenced deps in established monorepo; stable pattern. ai
phantom-deps phantom-dep:calculate-elbow AI (phantom-deps): Re-exported meta-package dep, not directly imported by design. ai
dependencies unvetted-dep:@tscircuit/schematic-corpus AI (dependencies): First-party tscircuit org package, part of same monorepo family. ai
phantom-deps phantom-dep:@tscircuit/create-fdm-enclosure AI (phantom-deps): Official tscircuit scoped package, likely used indirectly via build/runtime wiring. ai
dependencies unvetted-dep:@tscircuit/create-fdm-enclosure AI (dependencies): First-party tscircuit org package, consistent with monorepo ecosystem. ai
phantom-deps phantom-dep:@resvg/resvg-js AI (phantom-deps): Bundled ecosystem dep, config-referenced not directly imported; stable false positive. ai
phantom-deps phantom-dep:jscad-planner AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. ai
phantom-deps phantom-dep:minicssgrid AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. ai
phantom-deps phantom-dep:s-expression AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. ai
phantom-deps phantom-dep:graphics-debug AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. ai
phantom-deps phantom-dep:circuit-to-svg AI (phantom-deps): Monorepo sub-package, consistent false positive pattern for tscircuit. ai
dependencies unvetted-dep:@tscircuit/react-fiber AI (dependencies): First-party @tscircuit org dependency, same maintainer/ecosystem. ai
phantom-deps phantom-dep:@tscircuit/schematic-autolayout AI (phantom-deps): Used via config/type references, not direct import; benign for this monorepo package. ai
phantom-deps phantom-dep:@tscircuit/props AI (phantom-deps): Used via config/type references, not direct import; benign for this monorepo package. ai
dependencies unvetted-dep:@tscircuit/builder AI (dependencies): First-party @tscircuit org dependency, same maintainer/ecosystem. ai
phantom-deps phantom-dep:kicadts AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. ai
phantom-deps phantom-dep:manifold-3d AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. ai
phantom-deps phantom-dep:@lume/kiwi AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. ai
phantom-deps phantom-dep:bpc-graph AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. ai
phantom-deps phantom-dep:spicets AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. ai
phantom-deps phantom-dep:poppygl AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. ai
phantom-deps phantom-dep:spicey AI (phantom-deps): Build/config-referenced dep, consistent with this package's structure across versions. ai
source-diff net-exec-file:dist/browser.min.js AI (source-diff): Legitimate browser bundle exported via package.json exports map; code samples show React/module boilerplate, not malware. ai
source-diff source-size-tripled AI (source-diff): Size increase reflects bundling of many deps into browser/webworker minified artifacts; expected for this package's architecture. ai
source-diff net-exec-file:dist/webworker.min.js AI (source-diff): Legitimate webworker bundle for tscircuit eval; consistent with documented build scripts and package structure. ai
phantom-deps phantom-dep:@tscircuit/krt-wasm AI (phantom-deps): Platform-specific binary package; legitimate implicit dependency for this monorepo. ai
source-diff encoded-string-file:dist/webworker.min.js AI (source-diff): Long string is SVG/CSS chart rendering code in a minified webworker bundle, not an obfuscated payload. ai
dependencies unvetted-dep:@tscircuit/solver-utils AI (dependencies): tscircuit first-party package; stable pattern across versions. ai
phantom-deps phantom-dep:@rollup/plugin-commonjs AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-node-resolve AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-typescript AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-json AI (phantom-deps): Build tooling; framework-scoped, loaded by convention. ai
phantom-deps phantom-dep:@tscircuit/alphabet AI (phantom-deps): Newly added tscircuit ecosystem dep; stable false positive. ai
phantom-deps phantom-dep:format-si-unit AI (phantom-deps): Utility dep; stable false positive. ai
phantom-deps phantom-dep:css-select AI (phantom-deps): Transitive dep; stable false positive. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Peer/bundled dep for browser build; stable false positive. ai
phantom-deps phantom-dep:flatbush AI (phantom-deps): Transitive spatial indexing dep; stable false positive. ai
phantom-deps phantom-dep:sucrase AI (phantom-deps): Build-time dep; stable false positive. ai
phantom-deps phantom-dep:comlink AI (phantom-deps): Used in web worker build; stable false positive. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): Build tool referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): Known implicit TypeScript runtime dep; stable false positive. ai
phantom-deps phantom-dep:debug AI (phantom-deps): Stable false positive; debug is a transitive runtime dep in this large meta-package. ai
phantom-deps phantom-dep:@tscircuit/infgrid-ijump-astar AI (phantom-deps): tscircuit ecosystem dep; stable false positive. ai
phantom-deps phantom-dep:@tscircuit/circuit-json-util AI (phantom-deps): tscircuit ecosystem dep; stable false positive. ai
phantom-deps phantom-dep:@tscircuit/checks AI (phantom-deps): tscircuit ecosystem dep; stable false positive. ai
phantom-deps phantom-dep:@tscircuit/math-utils AI (phantom-deps): tscircuit ecosystem dep; stable false positive. ai
phantom-deps phantom-dep:@tscircuit/runframe AI (phantom-deps): tscircuit ecosystem dep; stable false positive. ai
phantom-deps phantom-dep:@tscircuit/soup-util AI (phantom-deps): tscircuit ecosystem dep; stable false positive. ai
phantom-deps phantom-dep:transformation-matrix AI (phantom-deps): Math utility dep; stable false positive. ai
phantom-deps phantom-dep:svg-path-commander AI (phantom-deps): SVG utility dep; stable false positive. ai
phantom-deps phantom-dep:rollup-plugin-dts AI (phantom-deps): Build tool; stable false positive. ai
phantom-deps phantom-dep:calculate-packing AI (phantom-deps): Geometry dep; stable false positive. ai
phantom-deps phantom-dep:performance-now AI (phantom-deps): Polyfill dep; stable false positive. ai
dependencies unvetted-dep:@tscircuit/miniflex AI (dependencies): tscircuit first-party dep; stable. ai
dependencies unvetted-dep:@tscircuit/footprinter AI (dependencies): tscircuit first-party dep; stable. ai
dependencies unvetted-dep:kicad-to-circuit-json AI (dependencies): tscircuit ecosystem dep; stable. ai
dependencies unvetted-dep:circuit-json-to-spice AI (dependencies): tscircuit ecosystem dep; stable. ai
dependencies unvetted-dep:circuit-json-to-gltf AI (dependencies): tscircuit ecosystem dep; stable. ai
dependencies unvetted-dep:@tscircuit/matchpack AI (dependencies): tscircuit first-party dep; stable. ai
dependencies unvetted-dep:circuit-json-to-bpc AI (dependencies): tscircuit ecosystem dep; stable. ai
dependencies unvetted-dep:spicey AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:@tscircuit/alphabet AI (dependencies): tscircuit first-party dep; stable. ai
dependencies unvetted-dep:connectivity-map AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:calculate-elbow AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:@resvg/resvg-js AI (dependencies): Well-known SVG rendering library; stable for this package. ai
dependencies unvetted-dep:graphics-debug AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:circuit-to-svg AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:jscad-planner AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:s-expression AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:minicssgrid AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:bpc-graph AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:poppygl AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
dependencies unvetted-dep:kicadts AI (dependencies): tscircuit ecosystem dep; stable pattern across versions. ai
source-diff encoded-string-file:dist/browser.min.js AI (source-diff): tscircuit ships a minified browser bundle; long strings in dist/browser.min.js are CSS-in-JS and UI code, not malicious payloads. This is stable for this package. ai
publish-pattern new-deps-added AI (publish-pattern): svg-path-commander is a legitimate SVG utility; @tscircuit/alphabet is a first-party tscircuit package. Both additions are benign for this EDA library. ai
phantom-deps phantom-dep:react AI (phantom-deps): Bundled meta-package pattern; react is a legitimate peer/bundled dependency for this EDA toolkit. ai
phantom-deps phantom-dep:zod AI (phantom-deps): tscircuit is a bundled meta-package; phantom deps are expected false positives from the tsup build pattern where deps are bundled rather than directly imported. ai
phantom-deps phantom-dep:schematic-symbols AI (phantom-deps): Bundled meta-package pattern; legitimate tscircuit ecosystem dependency. ai
phantom-deps phantom-dep:circuit-json AI (phantom-deps): Bundled meta-package pattern; all @tscircuit ecosystem deps are expected to appear as phantom deps in this umbrella package. ai
phantom-deps phantom-dep:@tscircuit/footprinter AI (phantom-deps): Bundled meta-package pattern; legitimate tscircuit scoped dependency. ai
phantom-deps phantom-dep:@tscircuit/capacity-autorouter AI (phantom-deps): Bundled meta-package pattern; legitimate tscircuit scoped dependency. ai
provenance no-provenance AI (provenance): tscircuit is a well-established package (1302 days, 2774 versions); lack of Sigstore provenance is not a security concern for this package. ai

Versions (showing 100 of 1841)

Version Deps Published
0.0.1425 65 / 4
0.0.1424 65 / 4
0.0.1423 65 / 4
0.0.1422 65 / 4
0.0.1421 65 / 4
0.0.1420 65 / 4
0.0.1419 65 / 4
0.0.1418 65 / 4
0.0.1417 65 / 4
0.0.1416 65 / 4
0.0.1415 65 / 4
0.0.1414 65 / 4
0.0.1413 65 / 4
0.0.1412 65 / 4
0.0.1411 65 / 4
0.0.1410 65 / 4
0.0.1409 65 / 4
0.0.1408 65 / 4
0.0.1407 65 / 4
0.0.1406 65 / 4
0.0.1405 65 / 4
0.0.1404 65 / 4
0.0.1403 65 / 4
0.0.1402 65 / 4
0.0.1401 65 / 4
0.0.1400 65 / 4
0.0.1399 65 / 4
0.0.1398 65 / 4
0.0.1397 65 / 4
0.0.1396 65 / 4
0.0.1395 65 / 4
0.0.1394 65 / 4
0.0.1393 65 / 4
0.0.1392 65 / 4
0.0.1391 65 / 4
0.0.1390 65 / 4
0.0.1389 65 / 4
0.0.1388 65 / 4
0.0.1387 65 / 4
0.0.1386 65 / 4
0.0.1385 65 / 4
0.0.1384 65 / 4
0.0.1383 65 / 4
0.0.1382 65 / 4
0.0.1381 65 / 4
0.0.1380 65 / 4
0.0.1379 65 / 4
0.0.1378 65 / 4
0.0.1377 65 / 4
0.0.1376 65 / 4
0.0.1375 65 / 4
0.0.1374 65 / 4
0.0.1373 65 / 4
0.0.1371 65 / 4
0.0.1370 65 / 4
0.0.1369 65 / 4
0.0.1368 65 / 4
0.0.1367 65 / 4
0.0.1366 65 / 4
0.0.1365 65 / 4
0.0.1364 65 / 4
0.0.1363 65 / 4
0.0.1362 65 / 4
0.0.1361 65 / 4
0.0.1360 65 / 4
0.0.1359 65 / 4
0.0.1358 65 / 4
0.0.1357 65 / 4
0.0.1356 65 / 4
0.0.1355 65 / 4
0.0.1354 65 / 4
0.0.1353 65 / 4
0.0.1352 65 / 4
0.0.1351 65 / 4
0.0.1350 65 / 4
0.0.1349 65 / 4
0.0.1348 65 / 4
0.0.1347 65 / 4
0.0.1346 65 / 4
0.0.1345 65 / 4
0.0.1344 65 / 4
0.0.1343 65 / 4
0.0.1342 65 / 4
0.0.1341 65 / 4
0.0.1340 65 / 4
0.0.1339 65 / 4
0.0.1338 65 / 4
0.0.1337 65 / 4
0.0.1336 65 / 4
0.0.1335 65 / 4
0.0.1334 65 / 4
0.0.1333 65 / 4
0.0.1332 65 / 4
0.0.1331 65 / 4
0.0.1330 65 / 4
0.0.1329 65 / 4
0.0.1328 65 / 4
0.0.1327 65 / 4
0.0.1326 65 / 4
0.0.1325 65 / 4
Showing 100 of 1841 Next page →

v0.0.1425

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1424

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1423

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1422

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1421

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1420

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1419

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1418

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1417

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1416

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1415

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1414

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1413

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1412

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1411

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1410

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1409

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1408

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1407

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1406

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1405

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1404

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1403

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1402

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1401

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1400

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1399

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1397

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1396

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1395

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1394

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1393

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1391

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1390

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1389

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1388

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1387

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1386

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1385

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1383

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1382

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1381

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1380

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1379

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1378

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1377

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1376

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1375

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1374

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1373

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1371

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1370

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1369

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1368

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1367

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1366

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1365

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1364

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1363

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1362

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1361

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1360

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1359

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1358

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1357

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1356

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1355

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1354

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1353

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1352

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1351

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1350

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1349

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1348

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1347

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1346

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1345

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1344

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1343

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1342

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1341

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1340

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1339

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1338

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1337

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1336

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1335

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1334

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1333

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1332

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1325

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.