@axinom/mosaic-id-guard
Authentication and authorization helpers for Axinom Mosaic services
5
Versions
PROPRIETARY
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
schwendneraxinom_kuzminruwanxaxinomnpm
Keywords
axinommosaicaxinom mosaic
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Proprietary internal library; no public repo/homepage is expected for this package family. | ai | |
| dependencies | unvetted-dep:express-bearer-token | AI (dependencies): express-bearer-token is a well-known, benign Express middleware; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): pg is a legitimate runtime dep for a DB-backed auth guard; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:amqplib | AI (phantom-deps): amqplib is a legitimate message-bus dep; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:graphql-tag | AI (phantom-deps): graphql-tag is a legitimate dep for a GraphQL-integrated auth library; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:subscriptions-transport-ws | AI (phantom-deps): subscriptions-transport-ws is a legitimate dep for WebSocket subscription auth; phantom-dep heuristic fires on config-file references. | ai |