unique-slug
Generate a unique character string suitible for use in files and URLs.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): npm CLI packages migrated to GitHub Actions publishing with SLSA provenance; this is the new standard for the npm org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Normal npm CLI team member rotation; package remains under the official npm GitHub org. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Normal npm CLI team member rotation; fritzy's removal is consistent with team changes. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Stable utility package with infrequent updates; dormancy is expected for a simple slug generator. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 7.0.0 | 1 / 2 | |
| 6.0.0 | 1 / 3 | |
| 5.0.0 | 1 / 3 | |
| 4.0.0 | 1 / 3 | |
| 3.0.0 | 1 / 3 | |
| 2.0.2 | 1 / 2 | |
| 2.0.1 | 1 / 2 | |
| 2.0.0 | 1 / 2 | |
| 1.0.0 | 0 / 2 |
v7.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.0
2 findingsThis version was published by a different npm account than previous versions on 2025-10-22. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version was published by a different npm account than previous versions on 2024-09-25. This could indicate a legitimate maintainer transition or an account compromise.