@tachybase/database
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:graphlib | AI (phantom-deps): graphlib is a declared dependency used in config/build context; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:cron-parser | AI (phantom-deps): cron-parser declared dependency; phantom-dep heuristic false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo component; missing description/repo/keywords is cosmetic, not indicative of malice. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): 127.0.0.1 in mock-database.js test hook is localhost test infrastructure, not exfiltration. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() inside a Proxy handler is standard JS pattern, not obfuscation. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 1.6.12 | 19 / 5 | |
| 1.6.10 | 19 / 5 | |
| 1.6.9 | 19 / 5 | |
| 1.6.3 | 19 / 5 | |
| 1.6.2 | 19 / 5 | |
| 1.3.54 | 19 / 5 | |
| 1.3.48 | 19 / 4 | |
| 1.3.47 | 19 / 4 | |
| 1.3.33 | 20 / 3 | |
| 1.3.28 | 21 / 3 | |
| 1.3.26 | 21 / 3 | |
| 1.2.15 | 22 / 3 | |
| 1.2.8 | 22 / 3 | |
| 1.2.7 | 22 / 3 | |
| 1.2.2 | 22 / 3 | |
| 1.1.25 | 22 / 3 | |
| 1.1.21 | 22 / 3 | |
| 1.1.2 | 22 / 3 |
v1.6.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.54
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.48
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.