← Home

rc-table

table ui component for react

100
Versions
MIT
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

benjycuiyesmeckafc163yiminghedxq613paranoidjkzombiejxrkffggmadccc

Keywords

reactreact-tabletablecomponentui

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:browserify-jsx AI (dependencies): browserify-jsx is a build-time JSX transform tool used in browserify config only; not a runtime dependency with security implications for consumers of rc-table. ai
phantom-deps phantom-dep:rc-util AI (phantom-deps): rc-util is a legitimate dependency used transitively in rc-table; phantom-dep warnings are expected for this package type. ai
phantom-deps phantom-dep:shallowequal AI (phantom-deps): shallowequal is a legitimate dependency used transitively; phantom-dep warnings are expected for this package type. ai
phantom-deps phantom-dep:lodash.get AI (phantom-deps): lodash.get is a legitimate dependency used transitively; phantom-dep warnings are expected for this package type. ai
phantom-deps phantom-dep:warning AI (phantom-deps): warning is a legitimate dependency used transitively; phantom-dep warnings are expected for this package type. ai
phantom-deps phantom-dep:mini-store AI (phantom-deps): mini-store is properly declared in dependencies; phantom-dep on stable packages is a false positive. ai
phantom-deps phantom-dep:react-lifecycles-compat AI (phantom-deps): react-lifecycles-compat is properly declared in dependencies; phantom-dep on stable packages is a false positive. ai
phantom-deps phantom-dep:component-classes AI (phantom-deps): component-classes is properly declared in dependencies; phantom-dep on stable packages is a false positive. ai
phantom-deps phantom-dep:prop-types AI (phantom-deps): prop-types is properly declared in dependencies; phantom-dep on stable packages is a false positive. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Lodash is properly declared in dependencies and used indirectly; phantom-dep on stable packages is a false positive. ai
source-diff net-exec-file:dist/rc-table.min.js AI (source-diff): Minified webpack UMD bundle; same false positive pattern as the non-minified dist file. Stable for this package. ai
source-diff net-exec-file:dist/rc-table.js AI (source-diff): Standard webpack UMD bundle for a React component library; call() and network patterns are from webpack runtime and bundled deps, not malicious. ai
source-diff large-new-source-files AI (source-diff): rc-table grew from v3.x to v7.x; large file count increase reflects years of legitimate feature development, not injected code. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps (classnames, rc-util, rc-virtual-list, rc-resize-observer, @babel/runtime, @rc-component/context) are legitimate react-component ecosystem packages. ai
source-diff source-size-tripled AI (source-diff): Size increase from 9KB to 385KB reflects major version evolution (v3→v7) with TypeScript, virtual list, and other features added over years. ai
provenance publisher-changed AI (provenance): yiminghe is a known Alibaba/Ant Design contributor and co-maintainer in the same react-component org; transition from dxq613 is a legitimate handoff within the same organization. ai
provenance no-provenance AI (provenance): Package was published in 2015, well before Sigstore provenance was available; no-provenance is expected for this era. ai
maintainer-change maintainer-added AI (maintainer-change): yiminghe is a long-standing ecosystem contributor (first seen ~4157 days ago) and is listed as a co-maintainer in package.json; addition is legitimate. ai
phantom-deps phantom-dep:browserify-shim AI (phantom-deps): browserify-shim is declared in dependencies and referenced in browserify-shim config — not a phantom dep, just an indirect usage pattern. ai
phantom-deps phantom-dep:browserify-jsx AI (phantom-deps): browserify-jsx is declared in dependencies and referenced in browserify transform config — not a phantom dep, just an indirect usage pattern. ai
install-scripts install-script:install AI (install-scripts): Install script runs 'gulp config', a standard build configuration step in this package's documented workflow. No network fetching or malicious behavior. ai
semgrep semgrep:child-process-exec AI (semgrep): cp.exec in gulpfile.js runs git commands for release tagging — standard dev tooling, not reachable at install or runtime. ai
semgrep semgrep:child-process-import AI (semgrep): child_process is used only in gulpfile.js for dev tooling (git tagging). Not reachable during normal install or runtime. ai

Versions (showing 100 of 414)

Version Deps Published
7.55.1 6 / 45
7.55.0 6 / 45
7.54.0 6 / 45
7.53.1 6 / 45
7.53.0 6 / 45
7.52.7 6 / 45
7.52.6 6 / 45
7.52.5 6 / 45
7.52.4 6 / 45
7.52.3 6 / 45
7.52.1 6 / 45
7.52.0 6 / 45
7.51.1 6 / 45
7.51.0 6 / 45
7.50.5 6 / 45
7.50.4 6 / 45
7.50.3 6 / 45
7.50.2 6 / 45
7.50.1 6 / 45
7.50.0 6 / 45
7.49.0 6 / 45
7.48.1 6 / 45
7.48.0 6 / 45
7.47.5 6 / 45
7.47.4 6 / 45
7.47.3 6 / 45
7.47.2 6 / 45
7.47.1 6 / 44
7.47.0 6 / 44
7.46.2 6 / 44
7.46.1 6 / 44
7.46.0 6 / 44
7.45.7 6 / 44
7.45.6 6 / 44
7.45.5 6 / 44
7.45.4 6 / 44
7.45.3 6 / 44
7.45.2 6 / 44
7.45.1 6 / 44
7.45.0 6 / 44
7.44.0 6 / 44
7.43.1 6 / 44
7.43.0 6 / 44
7.42.0 6 / 44
7.41.0 6 / 44
7.40.0 6 / 44
7.39.0 6 / 44
7.38.1 6 / 45
7.38.0 6 / 45
7.37.0 6 / 45
7.36.1 6 / 45
7.36.0 6 / 41
7.35.2 6 / 41
7.35.1 6 / 41
7.35.0 6 / 41
7.34.4 6 / 41
7.34.3 6 / 41
7.34.2 6 / 41
7.34.1 6 / 41
7.34.0 6 / 41
7.33.4 6 / 41
7.33.3 6 / 41
7.33.2 6 / 41
7.33.1 6 / 41
7.33.0 6 / 41
7.32.3 5 / 40
7.32.2 5 / 40
7.32.1 5 / 38
7.32.0 5 / 38
7.31.1 5 / 38
7.31.0 5 / 38
7.30.4 5 / 36
7.30.3 5 / 34
7.30.2 5 / 34
7.30.1 5 / 34
7.30.0 5 / 34
7.29.1 5 / 34
7.29.0 5 / 34
7.28.3 5 / 35
7.28.2 5 / 35
7.28.1 5 / 35
7.28.0 5 / 35
7.27.2 5 / 36
7.27.1 5 / 35
7.27.0 5 / 35
7.26.0 5 / 35
7.25.3 5 / 35
7.25.2 5 / 35
7.25.1 5 / 35
7.25.0 5 / 35
7.24.3 5 / 35
7.24.2 5 / 35
7.24.1 5 / 35
7.24.0 5 / 35
7.23.2 5 / 35
7.23.1 5 / 35
7.23.0 5 / 35
7.22.2 5 / 35
7.22.1 5 / 35
7.22.0 5 / 35
Showing 100 of 414 Next page →

v7.55.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.55.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.54.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.53.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.53.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.52.7

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2025-09-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-09-05. This could indicate a legitimate maintainer transition or an account compromise.

v7.52.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.52.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.52.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.52.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2025-09-01) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-09-01. This could indicate a legitimate maintainer transition or an account compromise.

v7.52.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2025-08-29) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-08-29. This could indicate a legitimate maintainer transition or an account compromise.

v7.52.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2025-08-26) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-08-26. This could indicate a legitimate maintainer transition or an account compromise.

v7.51.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.51.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.50.5

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2025-05-12) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-05-12. This could indicate a legitimate maintainer transition or an account compromise.

v7.50.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.50.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.50.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.50.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-12-30) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-12-30. This could indicate a legitimate maintainer transition or an account compromise.

v7.50.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-12-30) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-12-30. This could indicate a legitimate maintainer transition or an account compromise.

v7.49.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.48.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.48.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-09-29) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-09-29. This could indicate a legitimate maintainer transition or an account compromise.

v7.47.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.47.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.47.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-08-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-08-15. This could indicate a legitimate maintainer transition or an account compromise.

v7.47.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-08-13) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-08-13. This could indicate a legitimate maintainer transition or an account compromise.

v7.47.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.47.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.46.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.46.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.46.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.45.7

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yiminghe → zombiej (on 2024-05-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-05-27. This could indicate a legitimate maintainer transition or an account compromise.

v7.45.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yiminghe → zombiej (on 2024-05-17) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-05-17. This could indicate a legitimate maintainer transition or an account compromise.

v7.45.5

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yiminghe → afc163 (on 2024-04-30) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-04-30. This could indicate a legitimate maintainer transition or an account compromise.

v7.45.4

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-04-03) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-04-03. This could indicate a legitimate maintainer transition or an account compromise.

v7.45.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.44.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.43.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.43.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.42.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.41.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.40.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.39.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.38.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-01-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-01-27. This could indicate a legitimate maintainer transition or an account compromise.

v7.38.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.37.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2024-01-12) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-01-12. This could indicate a legitimate maintainer transition or an account compromise.

v7.36.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.36.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.35.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.35.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.35.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.34.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.34.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.34.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.34.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.34.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.33.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.33.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.33.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.33.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.33.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2023-08-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-08-25. This could indicate a legitimate maintainer transition or an account compromise.

v7.32.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2023-08-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-08-15. This could indicate a legitimate maintainer transition or an account compromise.

v7.32.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.32.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.32.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2023-05-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-05-05. This could indicate a legitimate maintainer transition or an account compromise.

v7.31.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2023-03-17) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-03-17. This could indicate a legitimate maintainer transition or an account compromise.

v7.31.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.30.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.30.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.30.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.30.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.30.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2023-01-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-01-05. This could indicate a legitimate maintainer transition or an account compromise.

v7.29.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2023-01-04) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-01-04. This could indicate a legitimate maintainer transition or an account compromise.

v7.29.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.28.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2022-12-21) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-12-21. This could indicate a legitimate maintainer transition or an account compromise.

v7.28.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.28.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2022-10-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-10-27. This could indicate a legitimate maintainer transition or an account compromise.

v7.28.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2022-10-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-10-25. This could indicate a legitimate maintainer transition or an account compromise.

v7.27.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2022-09-06) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-09-06. This could indicate a legitimate maintainer transition or an account compromise.

v7.27.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2022-08-26) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-08-26. This could indicate a legitimate maintainer transition or an account compromise.

v7.27.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.25.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.25.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.25.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.25.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2022-07-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-07-05. This could indicate a legitimate maintainer transition or an account compromise.

v7.24.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.24.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.24.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.24.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.23.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → madccc (on 2022-03-21) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-03-21. This could indicate a legitimate maintainer transition or an account compromise.

v7.23.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2022-03-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-03-18. This could indicate a legitimate maintainer transition or an account compromise.

v7.23.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: afc163 → zombiej (on 2022-02-16) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-02-16. This could indicate a legitimate maintainer transition or an account compromise.

v7.22.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.22.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.22.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zombiej → afc163 (on 2022-01-04) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-01-04. This could indicate a legitimate maintainer transition or an account compromise.