← Home

@jest/transform

97
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

aaronabramovsimenbrickhanloniiopenjs-operationscpojer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established Jest package; provenance attestation is a best-practice enhancement, not a security blocker. ai
publish-pattern new-deps-added AI (publish-pattern): pirates is a well-known, legitimate require-hook package appropriate for a Jest transform module; its addition is consistent with Jest's documented module transformation architecture. ai
provenance publisher-changed AI (provenance): scotthovestadt is a known Jest/Facebook maintainer with a strong track record (1610 approved packages). The transition from rubennorte is a legitimate team handoff within the Jest core team. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers (rubennorte, fb, scotthovestadt, davidzilburg) are Meta/FB accounts consistent with the documented Jest org migration to jestjs. ai
maintainer-change maintainer-added AI (maintainer-change): cpojer (Christoph Nakazawa) is a founding Jest contributor; addition reflects the known Meta→jestjs org transition, not a suspicious takeover. ai
dependencies unvetted-dep:babel-plugin-istanbul AI (dependencies): babel-plugin-istanbul is the standard Babel plugin for Istanbul coverage instrumentation; expected in Jest's transform layer. ai
dependencies unvetted-dep:convert-source-map AI (dependencies): convert-source-map is a well-known source map utility; expected dependency for a transform/instrumentation package. ai
dependencies unvetted-dep:pirates AI (dependencies): pirates is a well-known, widely-used require hook library; a legitimate and expected dependency for Jest's transform layer. ai
dependencies unvetted-dep:jest-haste-map AI (dependencies): jest-haste-map is a core Jest monorepo package; always a legitimate dependency of @jest/transform. ai
dependencies unvetted-dep:jest-regex-util AI (dependencies): jest-regex-util is a core Jest monorepo utility; always a legitimate dependency of @jest/transform. ai
dependencies unvetted-dep:write-file-atomic AI (dependencies): write-file-atomic is a well-established npm package used for safe file writes; legitimate dependency for this package. ai
npm-metadata no-description AI (npm-metadata): Scoped monorepo package from the official Jest project; missing description is a cosmetic issue, not a risk indicator. ai
dependencies unvetted-dep:fast-json-stable-stringify AI (dependencies): fast-json-stable-stringify is a legitimate, widely-used utility that has been a stable dependency of @jest/transform across many versions. No security concern. ai
bogus-package bogus-package AI (bogus-package): Jest monorepo packages are always published at synchronized version numbers (e.g. 30.3.0 as first registry entry). Inflated semver, no keywords, and no description are expected for this package type. ai

Versions (showing 97 of 97)

Version Deps Published
30.4.1 14 / 6
30.4.0 14 / 6
30.3.0 14 / 6
30.2.0 15 / 7
30.1.2 15 / 7
30.1.1 15 / 7
30.1.0 15 / 7
30.0.5 15 / 7
30.0.4 15 / 7
30.0.2 15 / 7
30.0.1 15 / 7
30.0.0 15 / 7
29.7.0 15 / 7
29.6.4 15 / 7
29.6.3 15 / 7
29.6.2 15 / 7
29.6.1 15 / 7
29.6.0 15 / 7
29.5.0 15 / 7
29.4.3 15 / 7
29.4.2 15 / 7
29.4.1 15 / 7
29.4.0 15 / 7
29.3.1 15 / 7
29.3.0 15 / 7
29.2.2 15 / 7
29.2.1 15 / 7
29.2.0 15 / 7
29.1.2 15 / 7
29.1.0 15 / 7
29.0.3 15 / 7
29.0.2 15 / 7
29.0.1 15 / 7
29.0.0 15 / 7
28.1.3 15 / 8
28.1.2 15 / 8
28.1.1 15 / 8
28.1.0 15 / 8
28.0.3 15 / 8
28.0.2 15 / 8
28.0.1 15 / 8
28.0.0 15 / 8
27.5.1 15 / 8
27.5.0 15 / 9
27.4.6 15 / 9
27.4.5 15 / 9
27.4.4 15 / 9
27.4.2 15 / 9
27.4.1 15 / 9
27.4.0 15 / 9
27.3.1 15 / 9
27.3.0 15 / 9
27.2.5 15 / 9
27.2.4 15 / 9
27.2.3 15 / 9
27.2.2 15 / 9
27.2.1 15 / 9
27.2.0 15 / 9
27.1.1 15 / 9
27.1.0 15 / 9
27.0.6 15 / 9
27.0.5 15 / 9
27.0.2 15 / 9
27.0.1 15 / 9
27.0.0 15 / 9
26.6.2 15 / 9
26.6.1 15 / 8
26.6.0 15 / 8
26.5.2 15 / 8
26.5.0 15 / 8
26.3.0 15 / 8
26.2.2 15 / 8
26.2.1 15 / 8
26.2.0 15 / 8
26.1.0 15 / 8
26.0.1 15 / 8
26.0.0 15 / 8
25.5.1 16 / 8
25.5.0 16 / 8
25.4.0 16 / 8
25.3.0 16 / 8
25.2.6 16 / 8
25.2.4 16 / 8
25.2.3 16 / 8
25.2.1 16 / 8
25.2.0 16 / 8
25.1.0 16 / 7
25.0.0 16 / 6
24.9.0 16 / 6
24.8.0 15 / 6
24.7.1 15 / 6
24.7.0 15 / 6
24.6.0 15 / 6
24.5.0 15 / 6
24.4.0 15 / 6
24.3.1 15 / 6
24.3.0 15 / 6

v30.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.4.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: cpojer → simenb (on 2026-05-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-05-07. This could indicate a legitimate maintainer transition or an account compromise.

v30.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v30.0.5

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simenb → cpojer (on 2025-07-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-07-22. This could indicate a legitimate maintainer transition or an account compromise.

v30.0.4

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simenb → cpojer (on 2025-07-02) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-07-02. This could indicate a legitimate maintainer transition or an account compromise.

v30.0.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simenb → cpojer (on 2025-06-19) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-06-19. This could indicate a legitimate maintainer transition or an account compromise.

v30.0.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simenb → cpojer (on 2025-06-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-06-18. This could indicate a legitimate maintainer transition or an account compromise.

v30.0.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: simenb → cpojer (on 2025-06-10) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-06-10. This could indicate a legitimate maintainer transition or an account compromise.

v29.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v29.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v28.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.2.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.2.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.0.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.5.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.0.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: scotthovestadt → simenb (on 2020-05-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-05-05. This could indicate a legitimate maintainer transition or an account compromise.

v26.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.5.1

2 findings
HIGH Publisher changed: rubennorte → simenb (on 2020-04-29) provenance

This version was published by a different npm account than previous versions on 2020-04-29. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.5.0

2 findings
HIGH Publisher changed: rubennorte → simenb (on 2020-04-28) provenance

This version was published by a different npm account than previous versions on 2020-04-28. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.3.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidzilburg → simenb (on 2020-04-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-04-08. This could indicate a legitimate maintainer transition or an account compromise.

v25.2.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidzilburg → simenb (on 2020-04-02) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-04-02. This could indicate a legitimate maintainer transition or an account compromise.

v25.2.4

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidzilburg → simenb (on 2020-03-29) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-03-29. This could indicate a legitimate maintainer transition or an account compromise.

v25.2.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidzilburg → simenb (on 2020-03-26) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-03-26. This could indicate a legitimate maintainer transition or an account compromise.

v25.2.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidzilburg → simenb (on 2020-03-26) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-03-26. This could indicate a legitimate maintainer transition or an account compromise.

v25.2.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidzilburg → simenb (on 2020-03-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-03-25. This could indicate a legitimate maintainer transition or an account compromise.

v25.1.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: scotthovestadt → davidzilburg (on 2020-01-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-01-22. This could indicate a legitimate maintainer transition or an account compromise.

v25.0.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rubennorte → scotthovestadt (on 2019-08-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2019-08-22. This could indicate a legitimate maintainer transition or an account compromise.

v24.9.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rubennorte → scotthovestadt (on 2019-08-16) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2019-08-16. This could indicate a legitimate maintainer transition or an account compromise.

v24.8.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rubennorte → scotthovestadt (on 2019-05-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2019-05-05. This could indicate a legitimate maintainer transition or an account compromise.

v24.7.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rubennorte → scotthovestadt (on 2019-04-04) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2019-04-04. This could indicate a legitimate maintainer transition or an account compromise.

v24.7.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rubennorte → scotthovestadt (on 2019-04-03) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2019-04-03. This could indicate a legitimate maintainer transition or an account compromise.

v24.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v24.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v24.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v24.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v24.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.