@as-integrations/koa
2
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
abernixsamchungyphryneasmateogordo
Keywords
GraphQLApolloServerKoaJavascript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): CI/CD publish with SLSA attestation; gitHead absence is a minor metadata gap, not a risk signal. | ai | |
| provenance | publisher-changed | AI (provenance): Legitimate org transition to GitHub Actions CI/CD with SLSA attestation; known Apollo ecosystem maintainers added. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are known Apollo/GraphQL ecosystem contributors; consistent with org-level ownership transfer. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Long gap explained by major version bump (v2) targeting Apollo Server 5.x; legitimate maintenance resumption. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped Apollo/Koa integration package; Levenshtein match to 'joi' is coincidental. | ai | |
| typosquat | typosquat.levenshtein:zod | AI (typosquat): Scoped Apollo/Koa integration package; Levenshtein match to 'zod' is coincidental. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Scoped Apollo/Koa integration package; Levenshtein match to 'got' is coincidental. | ai |
v2.0.0
3 findings
HIGH
Missing gitHead — previous versions had it
provenance
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
HIGH
Publisher changed: mateogordo → GitHub Actions (on 2026-06-28)
provenance
This version was published by a different npm account than previous versions on 2026-06-28. This could indicate a legitimate maintainer transition or an account compromise.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.