badges
The definitive collection of badges for rendering
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): The publisher change from bevryme to balupton occurred in 2020 and reflects a legitimate account transition by Benjamin Lupton, founder of bevry. Stable for this package. | ai | |
| phantom-deps | phantom-dep:surge | AI (phantom-deps): surge is a deployment tool referenced in scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): eslint is a linting tool used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:typedoc | AI (phantom-deps): typedoc is a documentation generator used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): prettier is a code formatter used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:projectz | AI (phantom-deps): projectz is a metadata tool used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): typescript is a compiler used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:valid-module | AI (phantom-deps): valid-module is a verification tool used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:assert-helpers | AI (phantom-deps): assert-helpers is a test utility used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:valid-directory | AI (phantom-deps): valid-directory is a verification tool used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:make-deno-edition | AI (phantom-deps): make-deno-edition is a build tool used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:eslint-config-bevry | AI (phantom-deps): eslint config used in eslintConfig; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:eslint-config-prettier | AI (phantom-deps): eslint config used in eslintConfig; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-prettier | AI (phantom-deps): eslint plugin used in eslintConfig; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): eslint parser used in eslintConfig; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:@bevry/update-contributors | AI (phantom-deps): contributor update tool used in npm scripts; phantom-dep pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:kava | AI (phantom-deps): kava is a test runner used in npm scripts; phantom-dep pattern is stable for this build-tool-heavy package. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): eslint plugin used in eslintConfig; phantom-dep pattern is stable for this package. | ai |
Versions (showing 68 of 68)
| Version | Deps | Published |
|---|---|---|
| 4.40.0 | 0 / 16 | |
| 4.39.0 | 0 / 16 | |
| 4.38.0 | 0 / 17 | |
| 4.37.0 | 0 / 18 | |
| 4.36.0 | 0 / 17 | |
| 4.35.0 | 0 / 17 | |
| 4.34.0 | 0 / 17 | |
| 4.33.0 | 0 / 17 | |
| 4.32.0 | 0 / 17 | |
| 4.31.0 | 0 / 17 | |
| 4.30.0 | 0 / 17 | |
| 4.29.0 | 0 / 18 | |
| 4.28.0 | 0 / 17 | |
| 4.27.0 | 0 / 17 | |
| 4.26.0 | 0 / 17 | |
| 4.25.0 | 0 / 17 | |
| 4.24.0 | 0 / 17 | |
| 4.23.0 | 0 / 17 | |
| 4.22.0 | 0 / 17 | |
| 4.21.0 | 0 / 17 | |
| 4.20.0 | 0 / 17 | |
| 4.19.0 | 0 / 17 | |
| 4.18.0 | 0 / 17 | |
| 4.17.0 | 0 / 17 | |
| 4.16.0 | 0 / 17 | |
| 4.15.1 | 0 / 17 | |
| 4.15.0 | 0 / 17 | |
| 4.14.0 | 0 / 17 | |
| 4.13.0 | 0 / 17 | |
| 4.12.0 | 1 / 17 | |
| 4.11.0 | 17 / 17 | |
| 4.10.0 | 17 / 17 | |
| 4.9.0 | 0 / 17 | |
| 4.8.0 | 0 / 17 | |
| 4.7.0 | 0 / 17 | |
| 4.6.0 | 0 / 16 | |
| 4.5.0 | 0 / 16 | |
| 4.4.0 | 0 / 16 | |
| 4.3.0 | 0 / 16 | |
| 4.2.0 | 0 / 16 | |
| 4.1.0 | 0 / 16 | |
| 4.0.0 | 0 / 15 | |
| 3.1.0 | 0 / 22 | |
| 3.0.0 | 0 / 22 | |
| 2.3.0 | 0 / 16 | |
| 2.2.0 | 0 / 16 | |
| 2.1.0 | 0 / 16 | |
| 2.0.0 | 0 / 16 | |
| 1.5.0 | 1 / 16 | |
| 1.4.0 | 1 / 16 | |
| 1.3.0 | 1 / 17 | |
| 1.2.9 | 1 / 17 | |
| 1.2.8 | 1 / 10 | |
| 1.2.7 | 1 / 10 | |
| 1.2.6 | 1 / 10 | |
| 1.2.5 | 1 / 10 | |
| 1.2.4 | 1 / 8 | |
| 1.2.3 | 1 / 8 | |
| 1.2.2 | 1 / 8 | |
| 1.2.1 | 1 / 8 | |
| 1.2.0 | 1 / 8 | |
| 1.1.2 | 1 / 7 | |
| 1.1.1 | 1 / 7 | |
| 1.1.0 | 1 / 7 | |
| 1.0.2 | 1 / 7 | |
| 1.0.1 | 0 / 7 | |
| 1.0.0 | 0 / 7 | |
| 0.1.0 | 0 / 7 |
v4.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.15.1
2 findingsThis version was published by a different npm account than previous versions on 2020-06-26. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.