@envelop/generic-auth
4
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
dotansimhaenisdenjotheguild-bot
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): theguild-bot is The Guild's CI automation account; publisher transition from dotansimha is expected for this org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): theguild-bot is a known trusted automation account for The Guild org; stable pattern across their packages. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Both new deps are established @graphql-tools/@whatwg-node packages from the same org; low supply-chain risk. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper; declared as direct dep and used implicitly by compiled output. | ai | |
| provenance | no-provenance | AI (provenance): Established envelop monorepo package; lack of provenance is consistent across all versions and not a risk indicator here. | ai |