@itentialopensource/adapter-db_mongo
Itential adapter to connect to mongo
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:preinstall | AI (install-scripts): Itential adapter setup script pattern; runs local node script, not arbitrary remote code. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used only in testRunner.js test utility, not in runtime adapter code. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads package.json for version info; path is controlled, not user-supplied. | ai | |
| phantom-deps | phantom-dep:mocha | AI (phantom-deps): mocha is listed as a runtime dependency and used in test scripts; phantom-dep is a false positive here. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 1.0.2 | 7 / 6 | |
| 1.0.1 | 7 / 6 | |
| 1.0.0 | 7 / 6 | |
| 0.11.6 | 7 / 6 | |
| 0.11.4 | 7 / 6 | |
| 0.11.3 | 7 / 6 |
v1.0.2
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.6
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.4
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.3
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.