Every package owned by acme, tracked daily.
Recent reports
Latest saved auditsConfiguration
One or more npm org slugs (up to 5).
Publishers to treat as automation. Note: npm cannot distinguish a human from that human’s CI token, so “manual” is a proxy, not proof.
Live log shows audit progress and warnings.
“Recency” is the latest dist-tag’s publish time. “Manual” means the publisher isn’t in your bot-exclusion list — npm can’t tell a human session from that account’s automation token.
User publish history
standalone — by npm accountVersions attributed to a specific npm publisher within the window. This scans that account’s maintained packages, optionally combined with packages from the last audit run.