← Home

@imtbl/passport

Passport module for Immutable SDK

12
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tcurtin88alex-immutableplatform-saimmutable-npm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@metamask/detect-provider AI (phantom-deps): Referenced in config files only; stable FP for this bundled SDK package. ai
phantom-deps phantom-dep:magic-sdk AI (phantom-deps): SDK dependency referenced via config/peer pattern, not direct import; stable FP for this package. ai
phantom-deps phantom-dep:@magic-ext/oidc AI (phantom-deps): Referenced in config files only; stable FP for this bundled SDK package. ai
phantom-deps phantom-dep:@magic-sdk/provider AI (phantom-deps): Referenced in config files only; stable FP for this bundled SDK package. ai
phantom-deps phantom-dep:ethers AI (phantom-deps): Declared runtime dep used via config/re-export; stable false positive for this monorepo SDK package. ai
phantom-deps phantom-dep:localforage AI (phantom-deps): Declared runtime dep used via config/re-export; stable false positive for this monorepo SDK package. ai
phantom-deps phantom-dep:@imtbl/toolkit AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo internal packages. ai
phantom-deps phantom-dep:oidc-client-ts AI (phantom-deps): Declared runtime dep used via config/re-export; stable false positive for this monorepo SDK package. ai

Versions (showing 12 of 12)

Version Deps Published
2.20.0 9 / 19
2.19.0 9 / 19
2.18.0 9 / 19
2.17.1 9 / 19
2.17.0 9 / 19
2.16.0 9 / 19
2.15.0 9 / 19
2.12.2 11 / 19
2.11.0 19 / 20
2.10.6 19 / 20
2.10.5 19 / 20
2.10.4 19 / 20

v2.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.12.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.10.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.10.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.10.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.