@quenty/userserviceutils
Utilities involving UserService in Roblox
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@quenty/playermock | AI (dependencies): Same-org Nevermore monorepo sibling package. | ai | |
| dependencies | unvetted-dep:@quentystudios/jest-lua | AI (dependencies): Known test-tooling dep used across Quenty's monorepo. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo lockstep publishing across many sibling packages, long track record. | ai | |
| phantom-deps | phantom-dep:@quentystudios/jest-lua | AI (phantom-deps): Lua test tooling not detectable via JS import scan; same publisher ecosystem. | ai | |
| phantom-deps | phantom-dep:@quenty/playermock | AI (phantom-deps): Same-org Lua dep, not JS-importable by design. | ai | |
| phantom-deps | phantom-dep:@quenty/nevermore-test-runner | AI (phantom-deps): Same-org Lua dep, not JS-importable by design. | ai | |
| phantom-deps | phantom-dep:@quenty/aggregator | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): only-allow pnpm is a standard package-manager enforcement pattern used consistently across this monorepo. | ai | |
| phantom-deps | phantom-dep:@quenty/servicebag | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai | |
| phantom-deps | phantom-dep:@quenty/baseobject | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai | |
| phantom-deps | phantom-dep:@quenty/rx | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai | |
| phantom-deps | phantom-dep:@quenty/maid | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai | |
| phantom-deps | phantom-dep:@quenty/math | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai | |
| phantom-deps | phantom-dep:@quenty/loader | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai | |
| phantom-deps | phantom-dep:@quenty/promise | AI (phantom-deps): Same-org Roblox/Lua monorepo; JS import detection is not applicable to Lua source packages. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 9.37.0 | 11 / 0 | |
| 9.36.0 | 11 / 0 | |
| 9.35.0 | 11 / 0 | |
| 9.34.0 | 8 / 0 | |
| 9.32.0 | 8 / 0 | |
| 9.31.1 | 8 / 0 | |
| 9.31.0 | 8 / 0 | |
| 9.30.2 | 8 / 0 | |
| 9.23.0 | 8 / 0 | |
| 9.22.5 | 8 / 0 | |
| 9.22.4 | 8 / 0 | |
| 9.22.3 | 8 / 0 | |
| 9.22.2 | 8 / 0 | |
| 9.22.1 | 8 / 0 | |
| 9.22.0 | 8 / 0 | |
| 9.21.0 | 8 / 0 | |
| 9.20.1 | 8 / 0 | |
| 9.20.0 | 8 / 0 | |
| 9.19.0 | 8 / 0 | |
| 9.18.3 | 8 / 0 | |
| 9.18.2 | 8 / 0 | |
| 9.18.1 | 8 / 0 | |
| 9.18.0 | 8 / 0 | |
| 9.17.2 | 8 / 0 | |
| 9.17.1 | 8 / 0 | |
| 9.17.0 | 8 / 0 | |
| 9.16.0 | 8 / 0 | |
| 9.15.0 | 8 / 0 | |
| 9.14.0 | 7 / 0 | |
| 9.13.0 | 7 / 0 | |
| 9.12.1 | 7 / 0 | |
| 9.12.0 | 7 / 0 | |
| 9.11.0 | 7 / 0 | |
| 9.10.0 | 7 / 0 | |
| 9.9.0 | 7 / 0 | |
| 9.8.0 | 7 / 0 | |
| 9.7.0 | 7 / 0 | |
| 9.6.1 | 7 / 0 | |
| 9.6.0 | 7 / 0 | |
| 9.5.0 | 7 / 0 | |
| 9.4.0 | 7 / 0 | |
| 9.3.0 | 7 / 0 |
v9.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.18.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.18.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.17.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.17.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.