@meistrari/auth-core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:better-call | AI (phantom-deps): better-call is a declared runtime dependency; phantom-dep heuristic false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org package with 51 versions and established publisher; missing metadata is a style issue, not a spam/malware indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established scoped package with clean publisher history; missing description is cosmetic. | ai | |
| provenance | no-provenance | AI (provenance): Published via GitHub Actions CI; lack of Sigstore attestation is common and not a risk signal for this package. | ai |
Versions (showing 66 of 66)
| Version | Deps | Published |
|---|---|---|
| 1.36.0 | 5 / 5 | |
| 1.35.0 | 5 / 5 | |
| 1.34.0 | 5 / 5 | |
| 1.33.1 | 5 / 5 | |
| 1.33.0 | 5 / 5 | |
| 1.32.0 | 5 / 5 | |
| 1.31.0 | 5 / 5 | |
| 1.30.0 | 5 / 5 | |
| 1.29.0 | 5 / 5 | |
| 1.28.2 | 5 / 5 | |
| 1.28.1 | 5 / 5 | |
| 1.28.0 | 5 / 5 | |
| 1.27.0 | 5 / 5 | |
| 1.26.0 | 5 / 5 | |
| 1.25.0 | 5 / 5 | |
| 1.24.0 | 5 / 5 | |
| 1.23.0 | 5 / 5 | |
| 1.22.0 | 5 / 5 | |
| 1.21.0 | 5 / 5 | |
| 1.20.1 | 5 / 5 | |
| 1.20.0 | 5 / 5 | |
| 1.19.0 | 5 / 5 | |
| 1.18.0 | 5 / 5 | |
| 1.17.1 | 5 / 5 | |
| 1.17.0 | 5 / 5 | |
| 1.16.0 | 5 / 5 | |
| 1.15.0 | 5 / 3 | |
| 1.14.0 | 5 / 3 | |
| 1.13.3 | 5 / 3 | |
| 1.13.2 | 4 / 3 | |
| 1.13.1 | 4 / 3 | |
| 1.13.0 | 4 / 3 | |
| 1.12.0 | 4 / 3 | |
| 1.11.8 | 4 / 3 | |
| 1.11.7 | 4 / 3 | |
| 1.11.6 | 4 / 3 | |
| 1.11.5 | 4 / 3 | |
| 1.11.4 | 7 / 3 | |
| 1.11.3 | 6 / 3 | |
| 1.11.2 | 6 / 3 | |
| 1.11.1 | 6 / 3 | |
| 1.11.0 | 6 / 3 | |
| 1.10.0 | 6 / 3 | |
| 1.9.0 | 6 / 3 | |
| 1.8.0 | 6 / 3 | |
| 1.7.4 | 6 / 3 | |
| 1.7.1 | 6 / 3 | |
| 1.7.0 | 6 / 3 | |
| 1.6.0 | 6 / 3 | |
| 1.5.2 | 6 / 3 | |
| 1.5.1 | 6 / 3 | |
| 1.5.0 | 6 / 3 | |
| 1.4.7 | 6 / 3 | |
| 1.4.6 | 6 / 3 | |
| 1.4.5 | 6 / 3 | |
| 1.4.4 | 6 / 3 | |
| 1.4.3 | 6 / 3 | |
| 1.4.2 | 6 / 3 | |
| 1.4.1 | 6 / 3 | |
| 1.4.0 | 6 / 3 | |
| 1.3.0 | 6 / 3 | |
| 1.2.1 | 6 / 3 | |
| 1.2.0 | 6 / 3 | |
| 1.1.1 | 5 / 3 | |
| 1.1.0 | 5 / 3 | |
| 1.0.0 | 5 / 3 |
v1.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.