@axinom/mosaic-id-guard
Authentication and authorization helpers for Axinom Mosaic services
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Proprietary internal library; no public repo/homepage is expected for this package family. | ai | |
| dependencies | unvetted-dep:express-bearer-token | AI (dependencies): express-bearer-token is a well-known, benign Express middleware; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): pg is a legitimate runtime dep for a DB-backed auth guard; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:amqplib | AI (phantom-deps): amqplib is a legitimate message-bus dep; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:graphql-tag | AI (phantom-deps): graphql-tag is a legitimate dep for a GraphQL-integrated auth library; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:subscriptions-transport-ws | AI (phantom-deps): subscriptions-transport-ws is a legitimate dep for WebSocket subscription auth; phantom-dep heuristic fires on config-file references. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 0.46.0 | 20 / 13 | |
| 0.44.0 | 20 / 11 | |
| 0.43.0 | 20 / 11 | |
| 0.42.6 | 20 / 11 | |
| 0.42.4 | 20 / 11 |
v0.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.44.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.43.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.42.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.42.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.