@feasibleone/blong-login
Login and authentication utilities for the Blong framework
20
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
kalin.krustev
Keywords
blongradframework
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Package publishes via GitHub Actions with SLSA provenance attestation; missing gitHead is expected in this CI publish flow. | ai | |
| phantom-deps | phantom-dep:@types/ut-function.cbc | AI (phantom-deps): Local file-dep types bundle; not a runtime import, stable false positive for this package. | ai | |
| npm-metadata | url-dep:@types/ut-function.cbc | AI (npm-metadata): file: dep is a local types bundle bundled with the package, not a remote URL; low supply-chain risk. | ai | |
| phantom-deps | phantom-dep:jose | AI (phantom-deps): Monorepo TypeScript package; deps declared in package.json but source not compiled into dist at publish time. | ai | |
| phantom-deps | phantom-dep:@feasibleone/blong | AI (phantom-deps): Same-org workspace dependency; expected phantom-dep in monorepo context. | ai | |
| phantom-deps | phantom-dep:ut-function.cbc | AI (phantom-deps): Same monorepo pattern; phantom-dep is a heuristic false positive here. | ai | |
| phantom-deps | phantom-dep:@sinclair/typebox | AI (phantom-deps): Same monorepo pattern; phantom-dep is a heuristic false positive here. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 1.8.0 | 3 / 7 | |
| 1.7.0 | 3 / 7 | |
| 1.6.8 | 3 / 6 | |
| 1.6.7 | 3 / 8 | |
| 1.6.6 | 3 / 8 | |
| 1.6.5 | 3 / 8 | |
| 1.6.4 | 3 / 8 | |
| 1.6.3 | 3 / 8 | |
| 1.6.2 | 3 / 8 | |
| 1.6.1 | 4 / 7 | |
| 1.6.0 | 4 / 7 | |
| 1.5.0 | 3 / 7 | |
| 1.4.0 | 3 / 7 | |
| 1.3.0 | 3 / 7 | |
| 1.2.0 | 3 / 7 | |
| 1.1.0 | 3 / 7 | |
| 1.0.7 | 3 / 7 | |
| 1.0.6 | 3 / 7 | |
| 1.0.5 | 3 / 7 | |
| 0.0.1 | 4 / 6 |
v1.8.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.