get-pkg-repo
Get repository user and project information from package.json file contents.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@hutson/parse-repository-url | AI (phantom-deps): @hutson/parse-repository-url is a declared runtime dep central to this package's purpose; phantom detection is a false positive. | ai | |
| phantom-deps | phantom-dep:through2 | AI (phantom-deps): through2 is a declared runtime dep used for stream processing; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:hosted-git-info | AI (phantom-deps): hosted-git-info is a declared runtime dep central to this package's purpose; phantom detection is a false positive. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): hutson is the long-standing contributor behind @hutson/* deps used throughout this package; transfer to them is legitimate and expected. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): hbetts removal paired with hutson addition reflects a legitimate maintainer handoff; repo URL and org remain unchanged. | ai | |
| phantom-deps | phantom-dep:meow | AI (phantom-deps): meow is a declared runtime dep used by the CLI entry point; phantom detection is a false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change from hbetts→hutson is the same person (Hutson Betts) renaming their npm scope; confirmed by matching dep rename pattern and strong track record. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 3.1M weekly downloads and trusted publisher; lack of Sigstore provenance is not a security risk for this package. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 5.0.0 | 4 / 11 | |
| 4.2.1 | 4 / 11 | |
| 4.2.0 | 4 / 11 | |
| 4.1.2 | 4 / 11 | |
| 4.1.1 | 4 / 11 | |
| 4.1.0 | 4 / 11 | |
| 4.0.2 | 4 / 11 | |
| 4.0.1 | 4 / 11 | |
| 4.0.0 | 4 / 11 | |
| 3.0.0 | 5 / 5 | |
| 2.0.0 | 5 / 5 | |
| 1.4.0 | 5 / 5 | |
| 1.3.0 | 5 / 5 | |
| 1.2.1 | 5 / 5 | |
| 1.2.0 | 5 / 5 | |
| 1.1.1 | 5 / 5 | |
| 1.1.0 | 5 / 5 | |
| 1.0.0 | 4 / 5 | |
| 0.1.0 | 4 / 5 | |
| 0.0.6 | 5 / 3 | |
| 0.0.5 | 5 / 3 | |
| 0.0.4 | 5 / 3 | |
| 0.0.3 | 5 / 3 | |
| 0.0.2 | 5 / 3 | |
| 0.0.1 | 5 / 1 | |
| 0.0.0 | 5 / 1 |
v5.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2021-09-03. This could indicate a legitimate maintainer transition or an account compromise.
v4.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
2 findingsThis version was published by a different npm account than previous versions on 2018-12-22. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.