No SLSA provenancenpm registry signaturesgitHead linked
Without SLSA provenance there is no cryptographic link between this
tarball and the public source — the axios compromise (March 2026)
relied on exactly this gap.
Maintainers
firebase-opsfeiyang.chengoogle-wombotchholland
Accepted risks
Findings the reviewer chose to accept rather than block on.
Source
Rule
Reason
Accepted by
When
provenance
publisher-changed
AI (provenance): google-wombot is a known Google automation account used for Firebase SDK publishing; publisher transitions between Google-controlled accounts are routine for this package family.
ai
maintainer-change
maintainer-removed
AI (maintainer-change): Maintainer removals in Firebase SDK packages reflect internal Google team changes, not hostile takeovers. Consistent with the google-wombot publisher transition.
ai
source-diff
source-size-tripled
AI (source-diff): This package ships only index.d.ts (TypeScript type definitions). Size increases reflect API surface growth, not injected payloads — no executable code is distributed.