libnpmfund
Programmatic API for npm fund
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers (fritzy, gar, lukekarrys) are known npm/GitHub staff; this is a routine internal team transition for an npm-owned package. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): libnpmfund is an official npm CLI package; 0.0.0 is a standard bootstrapping version for npm's own libraries, not a malware indicator. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Flag is triggered by isaacs being listed as a spam publisher, but isaacs is the npm founder. This is a stable false positive for npm-org packages. | ai | |
| provenance | missing-githead | AI (provenance): libnpmfund is an official npm CLI workspace package published by known npm org members; missing gitHead reflects a publish environment change, not a security concern. | ai | |
| provenance | publisher-changed | AI (provenance): reggi is a known npm/GitHub employee and established publisher; transition from owlstronaut to reggi on an official npm/cli workspace package is a legitimate internal handoff. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer rotation is routine in the npm CLI org; package is part of the official npm/cli monorepo published by GitHub Inc., making hostile takeover implausible. | ai | |
| dependencies | unvetted-dep:@npmcli/arborist | AI (dependencies): @npmcli/arborist is a first-party npm CLI dependency from the same GitHub org; its use in libnpmfund is expected and stable across versions. | ai | |
| provenance | no-provenance | AI (provenance): Official npm CLI workspace package from GitHub Inc.; lack of Sigstore provenance is not a meaningful risk signal for this well-known package. | ai |
Versions (showing 82 of 82)
| Version | Deps | Published |
|---|---|---|
| 7.0.23 | 1 / 3 | |
| 7.0.22 | 1 / 3 | |
| 7.0.21 | 1 / 3 | |
| 7.0.20 | 1 / 3 | |
| 7.0.19 | 1 / 3 | |
| 7.0.18 | 1 / 3 | |
| 7.0.17 | 1 / 3 | |
| 7.0.16 | 1 / 3 | |
| 7.0.15 | 1 / 3 | |
| 7.0.14 | 1 / 3 | |
| 7.0.13 | 1 / 3 | |
| 7.0.12 | 1 / 3 | |
| 7.0.11 | 1 / 3 | |
| 7.0.10 | 1 / 3 | |
| 7.0.9 | 1 / 3 | |
| 7.0.8 | 1 / 3 | |
| 7.0.7 | 1 / 3 | |
| 7.0.6 | 1 / 3 | |
| 7.0.5 | 1 / 3 | |
| 7.0.4 | 1 / 3 | |
| 7.0.3 | 1 / 3 | |
| 7.0.2 | 1 / 3 | |
| 7.0.1 | 1 / 3 | |
| 7.0.0 | 1 / 3 | |
| 6.0.5 | 1 / 3 | |
| 6.0.4 | 1 / 3 | |
| 6.0.3 | 1 / 3 | |
| 6.0.2 | 1 / 3 | |
| 6.0.1 | 1 / 3 | |
| 6.0.0 | 1 / 3 | |
| 5.0.12 | 1 / 3 | |
| 5.0.11 | 1 / 3 | |
| 5.0.10 | 1 / 3 | |
| 5.0.9 | 1 / 3 | |
| 5.0.8 | 1 / 3 | |
| 5.0.7 | 1 / 3 | |
| 5.0.6 | 1 / 3 | |
| 5.0.5 | 1 / 3 | |
| 5.0.4 | 1 / 3 | |
| 5.0.3 | 1 / 3 | |
| 5.0.2 | 1 / 3 | |
| 5.0.1 | 1 / 3 | |
| 5.0.0 | 1 / 3 | |
| 4.2.2 | 1 / 3 | |
| 4.2.1 | 1 / 3 | |
| 4.1.1 | 1 / 3 | |
| 4.1.0 | 1 / 3 | |
| 4.0.20 | 1 / 3 | |
| 4.0.19 | 1 / 3 | |
| 4.0.18 | 1 / 3 | |
| 4.0.17 | 1 / 3 | |
| 4.0.16 | 1 / 3 | |
| 4.0.15 | 1 / 3 | |
| 4.0.14 | 1 / 3 | |
| 4.0.13 | 1 / 3 | |
| 4.0.12 | 1 / 3 | |
| 4.0.11 | 1 / 3 | |
| 4.0.10 | 1 / 3 | |
| 4.0.9 | 1 / 3 | |
| 4.0.8 | 1 / 3 | |
| 4.0.7 | 1 / 3 | |
| 4.0.6 | 1 / 3 | |
| 4.0.5 | 1 / 3 | |
| 4.0.4 | 1 / 3 | |
| 4.0.3 | 1 / 3 | |
| 4.0.2 | 1 / 3 | |
| 4.0.1 | 1 / 3 | |
| 4.0.0 | 1 / 3 | |
| 3.0.5 | 1 / 3 | |
| 3.0.4 | 1 / 3 | |
| 3.0.3 | 1 / 3 | |
| 3.0.2 | 1 / 3 | |
| 3.0.1 | 1 / 2 | |
| 3.0.0 | 1 / 2 | |
| 2.0.2 | 1 / 1 | |
| 2.0.1 | 1 / 6 | |
| 2.0.0 | 1 / 6 | |
| 1.1.0 | 1 / 6 | |
| 1.0.2 | 1 / 3 | |
| 1.0.1 | 1 / 3 | |
| 1.0.0 | 1 / 3 | |
| 0.0.0 | 1 / 3 |
v7.0.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.18
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.
v7.0.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-02-11. This could indicate a legitimate maintainer transition or an account compromise.
v7.0.14
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-02-04. This could indicate a legitimate maintainer transition or an account compromise.
v7.0.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.6
2 findingsThis version was published by a different npm account than previous versions on 2025-07-24. This could indicate a legitimate maintainer transition or an account compromise.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.3
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.
v6.0.2
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.
v6.0.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
v6.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-05-15. This could indicate a legitimate maintainer transition or an account compromise.
v5.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-04-03. This could indicate a legitimate maintainer transition or an account compromise.
v5.0.5
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-02-28. This could indicate a legitimate maintainer transition or an account compromise.
v5.0.4
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-01-24. This could indicate a legitimate maintainer transition or an account compromise.
v5.0.3
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-01-10. This could indicate a legitimate maintainer transition or an account compromise.
v5.0.2
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-12-06. This could indicate a legitimate maintainer transition or an account compromise.
v5.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.2
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-02-28. This could indicate a legitimate maintainer transition or an account compromise.
v4.2.1
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-10-06. This could indicate a legitimate maintainer transition or an account compromise.
v4.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-08-31. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.20
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-08-31. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.19
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-07-05. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.18
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-06-21. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.17
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-05-03. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.16
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-04-19. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.15
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-04-05. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.14
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-03-30. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.13
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-03-08. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.11
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-02-22. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-02-07. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.8
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-01-25. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.7
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2023-01-12. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.5
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-11-30. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.4
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-11-16. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-11-02. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-10-26. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.5
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gar.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-11-03. This could indicate a legitimate maintainer transition or an account compromise.
v3.0.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-09-13. This could indicate a legitimate maintainer transition or an account compromise.
v3.0.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-08-31. This could indicate a legitimate maintainer transition or an account compromise.
v3.0.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-04-07. This could indicate a legitimate maintainer transition or an account compromise.
v3.0.1
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ruyadorno.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-03-08. This could indicate a legitimate maintainer transition or an account compromise.
v3.0.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-02-24. This could indicate a legitimate maintainer transition or an account compromise.
v2.0.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2022-01-05. This could indicate a legitimate maintainer transition or an account compromise.
v2.0.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2021-10-12. This could indicate a legitimate maintainer transition or an account compromise.
v2.0.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2021-10-05. This could indicate a legitimate maintainer transition or an account compromise.
v1.1.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2021-05-13. This could indicate a legitimate maintainer transition or an account compromise.
v1.0.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-12-08. This could indicate a legitimate maintainer transition or an account compromise.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.