@graphql-yoga/subscription
15
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
urigodotansimhakamilkisielawittydevelopertheguild-bot
Keywords
pubsubgraphqleventsubscription
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): theguild-bot is The Guild's established CI/CD publishing account with 8894 approved packages; transition from dotansimha to theguild-bot is a documented org-level automation shift, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): theguild-bot is The Guild's well-established automation account; addition is consistent with org-wide move to automated publishing with SLSA provenance. | ai | |
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation via Sigstore, which is a stronger supply chain integrity signal. Missing gitHead is a cosmetic CI config difference, not a security concern for this well-established monorepo package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper used implicitly in compiled output; declaring it as a dep without direct imports is the expected pattern for TS packages. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Empty description is a cosmetic issue in this monorepo sub-package; all other metadata (repo, author, license, keywords) is properly populated. | ai |