← Home

@feasibleone/blong-gogo

34
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kalin.krustev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@sinclair/typebox-codegen AI (phantom-deps): Codegen tool likely used in build step, not direct import. ai
phantom-deps phantom-dep:@fastify/deepmerge AI (phantom-deps): Common Fastify utility, likely used transitively/config; benign in this monorepo. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is own-org scoped config package, no material behavior change. ai
npm-metadata no-description AI (npm-metadata): Internal orchestrator package; missing description is cosmetic. ai
dependencies unvetted-dep:@feasibleone/blong-mock AI (dependencies): Same-org sibling package, part of this monorepo framework. ai
dependencies unvetted-dep:@feasibleone/blong-lib AI (dependencies): Same-org sibling package, part of this monorepo framework. ai
dependencies unvetted-dep:@feasibleone/blong-config AI (dependencies): Same-org sibling package, part of this monorepo framework. ai
dependencies unvetted-dep:@feasibleone/blong-template AI (dependencies): Same-org sibling package, part of this monorepo framework. ai
semgrep semgrep:hex-decode AI (semgrep): Legitimate binary type decoding in schema adapter, not payload hiding. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Fires inside a test asserting path-traversal is rejected with 404; not credential harvesting. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used for generic config object path traversal; standard pattern, not obfuscation. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 used to decode a permission map in JWT construction; no obfuscation or exfiltration pattern. ai
phantom-deps phantom-dep:ajv-formats AI (phantom-deps): Config-file reference only; stable false positive for this package. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Hardcoded 127.0.0.1:8200 is the standard HashiCorp Vault default endpoint; not exfiltration. ai
phantom-deps phantom-dep:@feasibleone/blong-kopi AI (phantom-deps): Same org scope; likely a sibling package used indirectly via config, not a direct import. ai
phantom-deps phantom-dep:mysql2 AI (phantom-deps): Config-file reference only; phantom-dep heuristic false positive for optional/peer deps. ai

Versions (showing 34 of 34)

Version Deps Published
1.27.0 58 / 9
1.26.0 56 / 9
1.25.1 50 / 9
1.25.0 50 / 9
1.23.0 50 / 8
1.22.0 50 / 8
1.19.0 50 / 8
1.17.1 50 / 9
1.14.1 49 / 6
1.13.4 49 / 6
1.13.1 51 / 6
1.12.2 50 / 6
1.12.1 50 / 6
1.12.0 50 / 6
1.11.2 50 / 6
1.11.1 50 / 6
1.11.0 50 / 6
1.10.4 50 / 6
1.10.3 50 / 6
1.10.2 50 / 6
1.10.1 50 / 6
1.10.0 50 / 6
1.9.3 50 / 6
1.9.2 50 / 6
1.9.1 50 / 6
1.9.0 50 / 6
1.8.1 50 / 6
1.8.0 50 / 6
1.7.3 50 / 6
1.7.2 50 / 6
1.7.1 50 / 6
1.7.0 50 / 6
1.6.7 50 / 6
1.6.6 50 / 6

v1.27.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.26.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.