Skip to content

v3.5.0+ missing npm provenance attestation #256

@JamieMagee

Description

@JamieMagee

v3.5.0+ were published without provenance attestation on npm: https://www.npmjs.com/package/react-lite-youtube-embed?activeTab=versions

Not a security issue, just a heads-up. Tools like Dependabot have started flagging when attestation disappears between versions, so downstream users may see warnings on these releases.

Worth just making sure newer versions are published with provenance.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Priority 1bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions