@credo-ts/drizzle-storage
5
Versions
—
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
No source commit
Maintainers
openwalletfoundationtimoglastragenaris
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Package migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern for this org going forward. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): genaris is a known contributor in the openwallet-foundation/credo-ts project; legitimate maintainer addition. | ai | |
| dependencies | unvetted-dep:shell | AI (dependencies): shell is used in CLI migration tooling to spawn child processes; consistent with package purpose across versions. | ai | |
| phantom-deps | phantom-dep:class-validator | AI (phantom-deps): class-validator used via decorators in config files; false positive for this framework. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread is in CLI migration subprocess spawn — standard pattern for inheriting env in child process, not a data leak. | ai | |
| phantom-deps | phantom-dep:class-transformer | AI (phantom-deps): class-transformer used via decorators in config files; false positive for this framework. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a declared runtime dep used in config files; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:tsyringe | AI (phantom-deps): tsyringe is a declared runtime dep used via decorators/config; false positive for this framework. | ai |