copy-file
Copy a file
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): Transfer from khoomeister to sindresorhus is a legitimate, documented handoff to one of npm's most trusted publishers. Repo URL confirms sindresorhus ownership. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change to sindresorhus is legitimate; package.json author, repo, and funding all confirm sindresorhus ownership. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): sindresorhus is a highly trusted npm publisher; addition is part of a legitimate package transfer. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of khoomeister is consistent with a full, legitimate transfer to sindresorhus. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects a full rewrite: ESM module, TypeScript types, custom error class, fs abstraction. No obfuscation or suspicious payloads flagged. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): graceful-fs and p-event are well-known, trusted packages in the sindresorhus ecosystem; no malicious signal. | ai |
v11.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.0.0
3 findingsAll previous maintainers (khoomeister) were replaced by new maintainers (sindresorhus). This is a strong signal of a potential package hijack and requires careful review.
This version was published by a different npm account than previous versions on 2023-11-05. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.