← Home

@feasibleone/blong-login

Login and authentication utilities for the Blong framework

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kalin.krustev

Keywords

blongradframework

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Package publishes via GitHub Actions with SLSA provenance attestation; missing gitHead is expected in this CI publish flow. ai
phantom-deps phantom-dep:@types/ut-function.cbc AI (phantom-deps): Local file-dep types bundle; not a runtime import, stable false positive for this package. ai
npm-metadata url-dep:@types/ut-function.cbc AI (npm-metadata): file: dep is a local types bundle bundled with the package, not a remote URL; low supply-chain risk. ai
phantom-deps phantom-dep:jose AI (phantom-deps): Monorepo TypeScript package; deps declared in package.json but source not compiled into dist at publish time. ai
phantom-deps phantom-dep:@feasibleone/blong AI (phantom-deps): Same-org workspace dependency; expected phantom-dep in monorepo context. ai
phantom-deps phantom-dep:ut-function.cbc AI (phantom-deps): Same monorepo pattern; phantom-dep is a heuristic false positive here. ai
phantom-deps phantom-dep:@sinclair/typebox AI (phantom-deps): Same monorepo pattern; phantom-dep is a heuristic false positive here. ai

Versions (showing 20 of 20)

Version Deps Published
1.8.0 3 / 7
1.7.0 3 / 7
1.6.8 3 / 6
1.6.7 3 / 8
1.6.6 3 / 8
1.6.5 3 / 8
1.6.4 3 / 8
1.6.3 3 / 8
1.6.2 3 / 8
1.6.1 4 / 7
1.6.0 4 / 7
1.5.0 3 / 7
1.4.0 3 / 7
1.3.0 3 / 7
1.2.0 3 / 7
1.1.0 3 / 7
1.0.7 3 / 7
1.0.6 3 / 7
1.0.5 3 / 7
0.0.1 4 / 6

v1.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.