@ip-location-db/asn
Ip to location database
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped IP-location-db package; 'asn' suffix match against 'qs' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:async | AI (typosquat): Scoped IP-location-db package; 'asn' suffix match against 'async' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped IP-location-db package; 'asn' suffix match against 'ajv' is a false positive. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 2.3.2026060719 | 0 / 0 | |
| 2.3.2026060619 | 0 / 0 | |
| 2.3.2026060513 | 0 / 0 | |
| 2.3.2026060510 | 0 / 0 | |
| 2.3.2026060419 | 0 / 0 | |
| 2.3.2026060412 | 0 / 0 | |
| 2.3.2026060410 | 0 / 0 | |
| 2.3.2026060407 | 0 / 0 | |
| 2.3.2026050219 | 0 / 0 | |
| 2.3.2026050119 | 0 / 0 | |
| 2.3.2026043019 | 0 / 0 | |
| 2.3.2026042819 | 0 / 0 |
v2.3.2026060719
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.2026060619
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.2026060513
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026060510
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026060419
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026060412
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026060410
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026060407
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026050219
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026050119
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.2026043019
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.