scandirectory
Scan a directory recursively with a lot of control and power
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): bevryme is the bevry org account; balupton (Benjamin Lupton) remains listed as maintainer in package.json and is the org founder. This is an org account publishing pattern, not a takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): editions is a bevry-maintained utility used across their ecosystem for multi-edition Node.js support; its addition is consistent with the new compiled edition directories in this release. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is explained by addition of two Babel-compiled edition directories (edition-node-21, edition-node-4) as part of the multi-edition build strategy introduced in this version. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 8.1.1 | 2 / 16 | |
| 8.1.0 | 2 / 16 | |
| 8.0.0 | 2 / 15 | |
| 7.3.0 | 3 / 14 | |
| 7.2.0 | 3 / 14 | |
| 7.1.0 | 3 / 14 | |
| 7.0.0 | 3 / 14 | |
| 6.18.0 | 2 / 10 | |
| 6.17.0 | 2 / 10 | |
| 6.16.0 | 2 / 10 | |
| 6.15.0 | 2 / 10 | |
| 6.14.0 | 2 / 10 | |
| 6.13.0 | 2 / 10 | |
| 6.12.0 | 2 / 10 | |
| 6.11.0 | 2 / 10 | |
| 6.10.0 | 2 / 10 | |
| 6.8.0 | 2 / 10 | |
| 6.7.0 | 2 / 10 | |
| 6.6.0 | 2 / 10 | |
| 6.5.0 | 2 / 10 | |
| 6.4.0 | 2 / 10 | |
| 6.3.0 | 2 / 10 | |
| 6.2.0 | 2 / 10 | |
| 6.1.0 | 2 / 10 | |
| 6.0.0 | 2 / 10 | |
| 5.3.0 | 2 / 9 | |
| 5.2.0 | 2 / 9 | |
| 5.1.0 | 2 / 9 | |
| 5.0.0 | 2 / 9 | |
| 4.1.0 | 3 / 13 | |
| 4.0.0 | 3 / 13 | |
| 3.0.1 | 3 / 7 | |
| 3.0.0 | 3 / 7 | |
| 2.5.0 | 3 / 5 |
v8.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.