@alwaysmeticulous/api
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; missing gitHead is a minor metadata gap, not a supply chain risk for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher is GitHub Actions with SLSA provenance attestation; this is an intentional CI/CD publishing transition for this package. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): Scoped package @alwaysmeticulous/api; suffix match against 'hapi' is a stable false positive. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package; suffix match against 'pg' is a stable false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package; suffix match against 'joi' is a stable false positive. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped package; suffix match against 'ajv' is a stable false positive. | ai |
Versions (showing 9 of 109)
| Version | Deps | Published |
|---|---|---|
| 2.152.0 | 0 / 0 | |
| 2.149.0 | 0 / 0 | |
| 2.148.0 | 0 / 0 | |
| 2.144.0 | 0 / 0 | |
| 2.141.0 | 0 / 0 | |
| 2.140.0 | 0 / 0 | |
| 2.139.0 | 0 / 0 | |
| 2.137.0 | 0 / 0 | |
| 2.133.0 | 0 / 0 |
v2.152.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.149.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.148.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.144.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.141.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.140.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.139.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.137.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.133.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.