@accounter/green-invoice-graphql
Graphql proxy for Green Invoice API
7
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
gilgardosh
Keywords
green invoicegreeninvoiceaccountancyaccountantaccountergraphqlmesh
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:.bob/cjs/mesh-artifacts/index.js | AI (source-diff): Generated GraphQL Mesh CJS build artifact with long export lines; not true obfuscation. | ai | |
| source-diff | obfuscated-file:.bob/esm/mesh-artifacts/index.js | AI (source-diff): Generated GraphQL Mesh ESM build artifact; long lines are export chains from schema generation. | ai | |
| source-diff | obfuscated-file:dist/cjs/mesh-artifacts/index.js | AI (source-diff): Generated GraphQL Mesh CJS dist artifact; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/esm/mesh-artifacts/index.js | AI (source-diff): Generated GraphQL Mesh ESM dist artifact; not obfuscated. | ai | |
| source-diff | obfuscated-file:src/mesh-artifacts/index.ts | AI (source-diff): Generated TypeScript mesh artifact with long type/export lines; not obfuscated. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from manual publish (gilgardosh) to GitHub Actions CI/CD with SLSA attestation; legitimate automation upgrade. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/config | AI (phantom-deps): Mesh config loader; stable FP. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/runtime | AI (phantom-deps): Mesh runtime loaded via config; stable FP. | ai | |
| phantom-deps | phantom-dep:path | AI (phantom-deps): Node built-in declared for bundler compat; stable FP. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/cross-helpers | AI (phantom-deps): Mesh cross-helpers loaded via config; stable FP. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/json-schema | AI (phantom-deps): Mesh handler loaded via config; stable FP. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): Peer dep of graphql-mesh; resolved at runtime via mesh config. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/http | AI (phantom-deps): Mesh plugin loaded via config, not direct import; stable FP. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/store | AI (phantom-deps): Mesh plugin loaded via config; stable FP. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/types | AI (phantom-deps): Mesh types used at build time via config; stable FP. | ai | |
| phantom-deps | phantom-dep:@graphql-mesh/utils | AI (phantom-deps): Mesh utility loaded via config; stable FP. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.8.6 | 10 / 5 | |
| 0.8.4 | 10 / 0 | |
| 0.8.1 | 10 / 0 | |
| 0.8.0 | 10 / 0 | |
| 0.7.4 | 10 / 0 | |
| 0.7.1 | 10 / 0 | |
| 0.6.0 | 10 / 5 |
v0.7.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.