@libp2p/interface-peer-info
Peer Info interface for libp2p
12
Versions
Apache-2.0 OR MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jacobheunnpm-service-account-libp2palanshawvascosantosachingbraindaviddias
Keywords
interfacelibp2p
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): libp2p monorepo packages are intentionally bootstrapped at 0.0.0; this is a documented pattern for this publisher and ecosystem, not a malware indicator. | ai | |
| dependencies | unvetted-dep:@libp2p/interface-peer-id | AI (dependencies): Unvetted dependency is a peer interface within the libp2p ecosystem; stable pattern for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change from achingbrain to npm-service-account-libp2p reflects a legitimate org-level transition to a shared libp2p service account; consistent across the libp2p package ecosystem. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Addition of jacobheun and npm-service-account-libp2p is consistent with the libp2p project's organizational publishing practices; no compromise indicators. | ai | |
| provenance | no-provenance | AI (provenance): Lack of Sigstore provenance is common across npm; not a disqualifier for established packages with strong publisher track record. | ai |