@quenty/teleportserviceutils
Utility functions for teleport srevice
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@quenty/promisemaid | AI (phantom-deps): Same-org Lua dependency; import heuristic doesn't scan Lua source. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo publishes many packages together in quick succession; benign pattern. | ai | |
| phantom-deps | phantom-dep:@quenty/playermock | AI (phantom-deps): Lua source, not scanned by JS import heuristic; same-org dep. | ai | |
| dependencies | unvetted-dep:@quenty/playermock | AI (dependencies): Same-org sibling package within Nevermore monorepo. | ai | |
| npm-metadata | url-dep:@quenty/loader | AI (npm-metadata): Monorepo devDependency file: reference to sibling package, not a supply-chain risk. | ai | |
| dependencies | unvetted-dep:@quentystudios/jest-lua | AI (dependencies): Test dep from Quenty's own studio scope, long-standing pattern across versions. | ai | |
| phantom-deps | phantom-dep:@quenty/remoting | AI (phantom-deps): Same-org sibling package in monorepo; Lua imports not detected by JS import scanner. | ai | |
| phantom-deps | phantom-dep:@quenty/servicebag | AI (phantom-deps): Same-org monorepo dep, consistent with other accepted phantom-deps in this package. | ai | |
| phantom-deps | phantom-dep:@quentystudios/jest-lua | AI (phantom-deps): Test tooling dep referenced in config, not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@quenty/nevermore-test-runner | AI (phantom-deps): Same-org monorepo test dep, consistent with existing accepted phantom-deps. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Quenty's monorepo publishes in bulk; long gaps between releases are normal for utility sub-packages. | ai | |
| phantom-deps | phantom-dep:@quenty/rx | AI (phantom-deps): Roblox/Lua package; JS import analysis is not applicable. Same-org dep declared correctly. | ai | |
| phantom-deps | phantom-dep:@quenty/valueobject | AI (phantom-deps): Roblox/Lua package; JS import analysis is not applicable. | ai | |
| phantom-deps | phantom-dep:@quenty/promise | AI (phantom-deps): Roblox/Lua package; JS import analysis is not applicable. | ai | |
| phantom-deps | phantom-dep:@quenty/loader | AI (phantom-deps): Roblox/Lua package; JS import analysis is not applicable. | ai | |
| phantom-deps | phantom-dep:@quenty/maid | AI (phantom-deps): Roblox/Lua package; JS import analysis is not applicable. | ai | |
| phantom-deps | phantom-dep:@quenty/brio | AI (phantom-deps): Roblox/Lua package; JS import analysis is not applicable. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): npx only-allow pnpm is a standard monorepo package manager enforcement; stable pattern across all NevermoreEngine packages. | ai |
Versions (showing 65 of 65)
| Version | Deps | Published |
|---|---|---|
| 10.2.3 | 12 / 1 | |
| 10.2.1 | 11 / 1 | |
| 10.0.0 | 11 / 1 | |
| 9.39.0 | 11 / 1 | |
| 9.38.1 | 11 / 1 | |
| 9.38.0 | 11 / 1 | |
| 9.37.0 | 10 / 1 | |
| 9.36.0 | 10 / 1 | |
| 9.35.0 | 9 / 1 | |
| 9.34.0 | 9 / 1 | |
| 9.33.0 | 6 / 1 | |
| 9.32.0 | 6 / 1 | |
| 9.31.1 | 6 / 1 | |
| 9.31.0 | 6 / 1 | |
| 9.30.2 | 6 / 1 | |
| 9.30.1 | 6 / 1 | |
| 9.30.0 | 6 / 1 | |
| 9.29.0 | 6 / 1 | |
| 9.28.0 | 6 / 1 | |
| 9.27.0 | 6 / 1 | |
| 9.26.0 | 6 / 1 | |
| 9.25.1 | 6 / 1 | |
| 9.25.0 | 6 / 1 | |
| 9.24.0 | 6 / 1 | |
| 9.23.2 | 6 / 1 | |
| 9.23.1 | 6 / 1 | |
| 9.23.0 | 6 / 1 | |
| 9.22.1 | 6 / 1 | |
| 9.22.0 | 6 / 1 | |
| 9.21.7 | 6 / 1 | |
| 9.21.6 | 6 / 1 | |
| 9.21.5 | 6 / 1 | |
| 9.21.4 | 6 / 1 | |
| 9.21.3 | 6 / 1 | |
| 9.21.2 | 6 / 1 | |
| 9.21.1 | 6 / 1 | |
| 9.21.0 | 6 / 1 | |
| 9.20.0 | 6 / 1 | |
| 9.19.0 | 6 / 1 | |
| 9.18.1 | 6 / 1 | |
| 9.18.0 | 6 / 1 | |
| 9.17.3 | 6 / 1 | |
| 9.17.2 | 6 / 1 | |
| 9.17.1 | 6 / 1 | |
| 9.17.0 | 6 / 1 | |
| 9.16.2 | 6 / 1 | |
| 9.16.1 | 6 / 1 | |
| 9.16.0 | 6 / 1 | |
| 9.15.0 | 6 / 1 | |
| 9.14.0 | 6 / 1 | |
| 9.13.0 | 6 / 1 | |
| 9.12.0 | 6 / 1 | |
| 9.11.1 | 6 / 1 | |
| 9.11.0 | 6 / 1 | |
| 9.10.0 | 6 / 1 | |
| 9.9.2 | 6 / 1 | |
| 9.9.1 | 6 / 1 | |
| 9.9.0 | 6 / 1 | |
| 9.8.1 | 6 / 1 | |
| 9.8.0 | 6 / 1 | |
| 9.7.0 | 6 / 1 | |
| 9.6.0 | 6 / 1 | |
| 9.5.0 | 6 / 1 | |
| 9.4.0 | 6 / 1 | |
| 9.3.0 | 6 / 1 |
v10.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.38.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.23.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.17.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.17.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.17.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.16.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.16.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.11.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.9.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.9.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.