Skip to content

"threat.metadata.provenance-regression" uses incorrect previous version for comparison #853

Description

@christophetd

Sample:

$  guarddog npm scan pi-subagents --version 0.42.1
── Initial execution ──
initial-access-risk: found 1 indicator
│ * threat.metadata.provenance-regression
│   Version 0.42.1 was published without npm provenance attestations, but the earlier version 0.37.1 had them. Losing provenance after previous versions carried it can indicate a publish made outside the normal CI-attested flow, as seen in the nx compromise.

Sounds like the earlier version here should be 0.42.0, not 0.37.1?

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions