@sourceloop/reporting-service
reporting-service.
9
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
samarpan_sfnpm-sourcefuseakshatdubeysfyeshasfabir.ganguly
Keywords
loopback-extensionloopback
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Automated CI publisher with SLSA provenance; maintainer rotation in a large org monorepo is expected, not a takeover signal. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance attestation; consistent with org-wide CI migration. | ai | |
| dependencies | unvetted-dep:sequelize | AI (dependencies): sequelize is a well-known ORM; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:@loopback/core | AI (dependencies): Core loopback framework dep; stable for all sourceloop packages. | ai | |
| dependencies | unvetted-dep:@sourceloop/core | AI (dependencies): First-party sourceloop core dep; stable for this package. | ai | |
| dependencies | unvetted-dep:@loopback/repository | AI (dependencies): Core loopback framework dep; stable for all sourceloop packages. | ai | |
| dependencies | unvetted-dep:loopback-connector-postgresql | AI (dependencies): Standard PostgreSQL connector for loopback; stable for this service. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a well-known implicit TypeScript runtime dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:db-migrate-pg | AI (phantom-deps): db-migrate-pg referenced in migration config files, not directly imported; expected pattern. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv used in config files, not directly imported in source; false positive for this package. | ai | |
| phantom-deps | phantom-dep:loopback-connector-postgresql | AI (phantom-deps): Connector loaded dynamically by LoopBack datasource config, not directly imported; expected pattern. | ai | |
| phantom-deps | phantom-dep:@loopback/openapi-v3 | AI (phantom-deps): Used via decorators/metadata, not direct import; false positive for LoopBack packages. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs node migration.js — standard DB migration for this reporting service; stable pattern across versions. | ai |