@milaboratories/pl-middle-layer
Pl Middle Layer
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@milaboratories/pl-http | AI (phantom-deps): Same-org scoped package; likely re-exported or used indirectly. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@milaboratories/pl-config | AI (phantom-deps): Same-org scoped package; likely re-exported or used indirectly. Stable false positive for this package. | ai |
Versions (showing 51 of 502)
| Version | Deps | Published |
|---|---|---|
| 1.64.23 | 30 / 8 | |
| 1.64.22 | 30 / 8 | |
| 1.64.21 | 30 / 8 | |
| 1.64.20 | 30 / 8 | |
| 1.64.19 | 30 / 8 | |
| 1.64.18 | 30 / 8 | |
| 1.64.17 | 30 / 8 | |
| 1.64.16 | 30 / 8 | |
| 1.64.15 | 30 / 8 | |
| 1.64.14 | 30 / 8 | |
| 1.64.13 | 30 / 8 | |
| 1.64.12 | 30 / 8 | |
| 1.64.11 | 30 / 8 | |
| 1.64.10 | 30 / 8 | |
| 1.64.9 | 30 / 8 | |
| 1.64.8 | 30 / 8 | |
| 1.64.7 | 30 / 8 | |
| 1.64.6 | 29 / 9 | |
| 1.64.5 | 29 / 9 | |
| 1.64.4 | 29 / 9 | |
| 1.64.3 | 29 / 9 | |
| 1.64.2 | 29 / 9 | |
| 1.64.1 | 29 / 9 | |
| 1.64.0 | 29 / 9 | |
| 1.63.2 | 29 / 9 | |
| 1.63.1 | 29 / 9 | |
| 1.63.0 | 29 / 9 | |
| 1.62.0 | 29 / 9 | |
| 1.61.12 | 29 / 9 | |
| 1.61.11 | 29 / 9 | |
| 1.61.10 | 29 / 9 | |
| 1.61.9 | 29 / 9 | |
| 1.61.8 | 29 / 9 | |
| 1.61.7 | 29 / 9 | |
| 1.61.6 | 29 / 9 | |
| 1.61.5 | 29 / 9 | |
| 1.61.4 | 29 / 9 | |
| 1.61.3 | 29 / 9 | |
| 1.61.2 | 29 / 9 | |
| 1.61.1 | 29 / 9 | |
| 1.61.0 | 29 / 9 | |
| 1.60.5 | 29 / 9 | |
| 1.60.4 | 29 / 9 | |
| 1.60.3 | 29 / 9 | |
| 1.60.2 | 29 / 9 | |
| 1.60.1 | 29 / 9 | |
| 1.60.0 | 29 / 9 | |
| 1.59.15 | 29 / 9 | |
| 1.59.14 | 29 / 9 | |
| 1.59.13 | 29 / 9 | |
| 1.59.12 | 29 / 9 |
v1.64.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.63.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.63.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.63.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.62.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.61.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.59.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.59.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.59.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.59.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.