← Home

projectz

Stop wasting time syncing and updating your project's README and Package Files!

100
Versions
Artistic-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

bevryme

Keywords

badgesbowerbower.jsonbrowserifybuildbuildtoolcomponentcomponent.jsondocumentationes2022generatorjquery.jsonjspmlicensemarkdownmetametabuildnodepackage.jsonprojectreadmetypedtypestypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Bevry org (bevryme) is the long-standing publisher; balupton remains active. Removed maintainers are historical contributors, consistent with routine cleanup rather than takeover. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are @bevry/* first-party packages from the same author, replacing @bevry/file in a routine refactor. No supply-chain risk. ai
provenance no-provenance AI (provenance): Established package from trusted publisher; absence of Sigstore provenance is a best-practice gap, not a security defect. ai
dependencies unvetted-dep:spdx-expression-parse AI (dependencies): spdx-expression-parse is a well-known SPDX license parser from the Linux Foundation ecosystem; its use in a license-metadata tool like projectz is expected and legitimate. ai

Versions (showing 100 of 115)

Version Deps Published
4.2.0 14 / 15
4.1.1 14 / 15
4.1.0 14 / 15
4.0.0 14 / 15
3.4.0 11 / 17
3.2.0 11 / 17
3.1.0 9 / 17
3.0.0 9 / 17
2.23.0 9 / 18
2.22.0 9 / 17
2.21.0 9 / 17
2.20.0 9 / 17
2.19.0 9 / 17
2.18.0 9 / 17
2.17.0 9 / 17
2.16.0 9 / 17
2.15.0 9 / 16
2.14.0 9 / 16
2.13.0 9 / 16
2.12.0 11 / 16
2.11.0 11 / 16
2.10.1 11 / 16
2.10.0 10 / 16
2.9.0 10 / 16
2.7.0 10 / 16
2.6.0 10 / 16
2.5.0 10 / 16
2.4.0 10 / 15
2.3.0 10 / 15
2.2.0 10 / 15
2.1.0 10 / 15
2.0.0 10 / 15
1.19.1 16 / 11
1.19.0 16 / 11
1.18.0 16 / 11
1.17.1 16 / 11
1.17.0 16 / 11
1.16.0 16 / 11
1.15.0 16 / 11
1.14.0 16 / 11
1.13.0 16 / 11
1.12.0 16 / 11
1.11.0 16 / 11
1.10.0 16 / 11
1.9.0 16 / 11
1.8.0 16 / 11
1.7.5 16 / 11
1.7.4 16 / 12
1.7.3 16 / 12
1.7.2 16 / 12
1.7.1 16 / 12
1.7.0 16 / 12
1.6.0 16 / 12
1.5.3 16 / 7
1.5.2 16 / 7
1.5.1 16 / 7
1.5.0 15 / 7
1.4.0 20 / 9
1.3.2 20 / 8
1.3.1 20 / 8
1.3.0 20 / 8
1.2.0 20 / 9
1.1.6 20 / 9
1.1.5 20 / 9
1.1.4 20 / 9
1.1.3 20 / 9
1.1.2 20 / 9
1.1.1 20 / 9
1.1.0 20 / 9
1.0.9 20 / 7
1.0.8 20 / 7
1.0.7 20 / 8
1.0.6 20 / 7
1.0.5 20 / 7
1.0.4 20 / 7
1.0.3 19 / 7
1.0.2 19 / 7
1.0.1 19 / 7
1.0.0 19 / 7
0.5.0 11 / 6
0.4.3 11 / 6
0.4.2 11 / 6
0.4.1 11 / 6
0.4.0 11 / 6
0.3.17 11 / 6
0.3.16 11 / 6
0.3.15 11 / 6
0.3.14 11 / 6
0.3.13 11 / 6
0.3.12 11 / 6
0.3.11 11 / 6
0.3.10 11 / 6
0.3.9 11 / 6
0.3.8 11 / 6
0.3.7 11 / 6
0.3.6 11 / 6
0.3.5 11 / 6
0.3.4 11 / 6
0.3.3 11 / 6
0.3.2 11 / 2
Showing 100 of 115 Next page →

v4.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.