@phosphor/messaging
10
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
blink1073phosphor-usersccolbert
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): blink1073 (Steven Silvester) was already a listed contributor in package.json before taking over publishing; legitimate handoff within the PhosphorJS project team. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): blink1073 is a highly trusted publisher (3747 approved packages) and was already a contributor; phosphor-user addition is consistent with org-level maintenance. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of 'phosphor' maintainer is consistent with a planned project transition; no malicious indicators present. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance by years; absence is expected for this vintage of PhosphorJS packages. | ai |