@apollo/protobufjs
Protocol Buffers for JavaScript (& TypeScript).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:jaguarjs-jsdoc | AI (npm-metadata): Dev-only doc theme URL dep from original author's repo, low risk. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): High-trust Apollo publisher with 2337 approved packages; dormancy consistent with stable library maintenance cadence. | ai | |
| provenance | no-provenance | AI (provenance): Established Apollo package with trusted publisher; lack of Sigstore provenance is a minor process gap, not a security risk for this package. | ai | |
| dependencies | unvetted-dep:@types/long | AI (dependencies): @types/long is a standard TypeScript type definition package for the long.js library, a well-known dependency in the protobufjs ecosystem. | ai | |
| dependencies | unvetted-dep:@protobufjs/fetch | AI (dependencies): @protobufjs/fetch is a core sub-package of the protobufjs ecosystem, maintained by the same org. Stable and expected dependency. | ai | |
| dependencies | unvetted-dep:@protobufjs/inquire | AI (dependencies): @protobufjs/inquire is a core sub-package of the protobufjs ecosystem, maintained by the same org. Stable and expected dependency. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from apollo-bot to glasser, a known Apollo GraphQL engineer with long npm history. Legitimate team transition, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): glasser and trevor.scheer are known Apollo GraphQL team members. Legitimate maintainer addition. | ai | |
| semgrep | semgrep:child-process-exec | AI (semgrep): child_process.exec used in CLI tool (pbts.js) to invoke jsdoc for TypeScript definition generation — legitimate CLI use, not a backdoor. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process imported only in CLI tooling (pbts.js) for jsdoc invocation — expected for a protobuf CLI tool. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in CLI tooling (pbjs.js) to resolve protobuf.js path at runtime — standard pattern for CLI tools, no arbitrary user input. | ai | |
| phantom-deps | phantom-dep:@types/long | AI (phantom-deps): @types/long is a TypeScript type definition package; not directly imported at runtime by convention — stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is a TypeScript type definition package; not directly imported at runtime — stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:long | AI (phantom-deps): long is a declared runtime dependency used transitively by protobuf.js for 64-bit integer support; phantom-dep false positive for this package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs a local script (scripts/postinstall.js) included in the package for CLI setup — stable, documented pattern for this Apollo protobuf.js fork. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 1.2.8 | 12 / 33 | |
| 1.2.4 | 13 / 33 | |
| 1.2.3 | 13 / 33 | |
| 1.0.5 | 13 / 33 | |
| 1.0.3 | 13 / 33 |
v1.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.