global-tld-list
List of Global TLDs
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with valid SLSA Sigstore attestation from the original repo (mastermunj/global-tld-list). This is a legitimate CI/CD migration, stable for this package going forward. | ai |
Versions (showing 100 of 409)
| Version | Deps | Published |
|---|---|---|
| 1.25.21 | 0 / 19 | |
| 1.25.20 | 0 / 19 | |
| 1.25.19 | 0 / 19 | |
| 1.25.18 | 0 / 19 | |
| 1.25.17 | 0 / 19 | |
| 1.25.16 | 0 / 19 | |
| 1.25.15 | 0 / 19 | |
| 1.25.14 | 0 / 19 | |
| 1.25.13 | 0 / 19 | |
| 1.25.12 | 0 / 19 | |
| 1.25.11 | 0 / 19 | |
| 1.25.10 | 0 / 19 | |
| 1.25.9 | 0 / 19 | |
| 1.25.8 | 0 / 19 | |
| 1.25.7 | 0 / 19 | |
| 1.25.6 | 0 / 19 | |
| 1.25.5 | 0 / 19 | |
| 1.25.4 | 0 / 19 | |
| 1.25.3 | 0 / 19 | |
| 1.25.2 | 0 / 19 | |
| 1.25.1 | 0 / 19 | |
| 1.25.0 | 0 / 19 | |
| 1.24.6 | 0 / 19 | |
| 1.24.5 | 0 / 19 | |
| 1.24.4 | 0 / 19 | |
| 1.24.3 | 0 / 19 | |
| 1.24.2 | 0 / 19 | |
| 1.24.1 | 0 / 19 | |
| 1.24.0 | 0 / 19 | |
| 1.23.108 | 0 / 19 | |
| 1.23.107 | 0 / 19 | |
| 1.23.106 | 0 / 19 | |
| 1.23.105 | 0 / 19 | |
| 1.23.104 | 0 / 19 | |
| 1.23.103 | 0 / 19 | |
| 1.23.102 | 0 / 19 | |
| 1.23.101 | 0 / 19 | |
| 1.23.100 | 0 / 19 | |
| 1.23.99 | 0 / 19 | |
| 1.23.98 | 0 / 19 | |
| 1.23.97 | 0 / 19 | |
| 1.23.96 | 0 / 19 | |
| 1.23.95 | 0 / 19 | |
| 1.23.94 | 0 / 19 | |
| 1.23.93 | 0 / 19 | |
| 1.23.92 | 0 / 19 | |
| 1.23.91 | 0 / 19 | |
| 1.23.90 | 0 / 19 | |
| 1.23.89 | 0 / 19 | |
| 1.23.88 | 0 / 19 | |
| 1.23.87 | 0 / 19 | |
| 1.23.86 | 0 / 19 | |
| 1.23.85 | 0 / 19 | |
| 1.23.84 | 0 / 19 | |
| 1.23.83 | 0 / 19 | |
| 1.23.82 | 0 / 19 | |
| 1.23.81 | 0 / 19 | |
| 1.23.80 | 0 / 19 | |
| 1.23.79 | 0 / 19 | |
| 1.23.78 | 0 / 19 | |
| 1.23.77 | 0 / 19 | |
| 1.23.76 | 0 / 19 | |
| 1.23.75 | 0 / 19 | |
| 1.23.74 | 0 / 19 | |
| 1.23.73 | 0 / 19 | |
| 1.23.72 | 0 / 19 | |
| 1.23.71 | 0 / 19 | |
| 1.23.70 | 0 / 19 | |
| 1.23.69 | 0 / 19 | |
| 1.23.68 | 0 / 19 | |
| 1.23.67 | 0 / 19 | |
| 1.23.66 | 0 / 19 | |
| 1.23.65 | 0 / 19 | |
| 1.23.64 | 0 / 19 | |
| 1.23.63 | 0 / 19 | |
| 1.23.62 | 0 / 19 | |
| 1.23.61 | 0 / 19 | |
| 1.23.60 | 0 / 19 | |
| 1.23.59 | 0 / 19 | |
| 1.23.47 | 0 / 19 | |
| 1.23.46 | 0 / 19 | |
| 1.23.45 | 0 / 19 | |
| 1.23.44 | 0 / 19 | |
| 1.23.43 | 0 / 19 | |
| 1.23.42 | 0 / 19 | |
| 1.23.41 | 0 / 19 | |
| 1.23.40 | 0 / 19 | |
| 1.23.39 | 0 / 19 | |
| 1.23.38 | 0 / 19 | |
| 1.23.37 | 0 / 19 | |
| 1.23.36 | 0 / 19 | |
| 1.23.35 | 0 / 19 | |
| 1.23.34 | 0 / 19 | |
| 1.23.33 | 0 / 19 | |
| 1.23.32 | 0 / 19 | |
| 1.23.31 | 0 / 19 | |
| 1.23.30 | 0 / 19 | |
| 1.23.29 | 0 / 19 | |
| 1.23.28 | 0 / 19 | |
| 1.23.27 | 0 / 19 |
v1.25.10
2 findingsThis version was published by a different npm account than previous versions on 2026-02-25. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.23.97
2 findingsThis version was published by a different npm account than previous versions on 2026-01-27. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.23.88
2 findingsThis version was published by a different npm account than previous versions on 2026-01-18. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.23.79
2 findingsThis version was published by a different npm account than previous versions on 2026-01-09. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.23.61
2 findingsThis version was published by a different npm account than previous versions on 2025-12-22. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.23.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.23.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.23.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.