@tmlmobilidade/backupd
A backup service for databases.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| license | copyleft-license:AGPL-3.0-or-later | AI (license): Intentional license choice; stable for this package. | ai | |
| dependencies | unvetted-dep:resolve-tspaths | AI (dependencies): Standard tsconfig path-resolution build tool. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/emails | AI (dependencies): Same-org internal dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/utils | AI (dependencies): Same-org internal dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/go-interfaces-godb | AI (dependencies): Same-org rename of previously vetted dependency. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/go-interfaces-godb | AI (phantom-deps): Same-org monorepo package, renamed sibling of previously accepted dep. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): First-party same-org dependency, not an unrelated third-party add. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/go-interfaces-go-db | AI (phantom-deps): Same-org scoped package, likely loaded by convention like siblings. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/go-interfaces-go-db | AI (dependencies): Same-org internal package, consistent with existing vetted @tmlmobilidade deps. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): react listed as a dependency in a backup service but not imported; likely a misconfiguration, not a security risk. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/dates | AI (dependencies): Internal org dependency from the same @tmlmobilidade scope; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/interfaces | AI (dependencies): Internal org dependency from the same @tmlmobilidade scope; stable pattern across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Org-internal package with consistent publishing pattern; provenance not enabled across the monorepo. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo with 237 versions; rapid publishes are consistent with automated CI releasing sibling packages simultaneously. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/types | AI (phantom-deps): Same-org package; stable false positive for this org's monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/utils | AI (phantom-deps): Same-org package; phantom-dep heuristic is a stable false positive for this org's monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/consts | AI (phantom-deps): Same-org package; stable false positive for this org's monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@types/archiver | AI (phantom-deps): Type-only package; not directly imported at runtime by design. | ai | |
| phantom-deps | phantom-dep:resolve-tspaths | AI (phantom-deps): Build tool referenced in scripts/config, not directly imported — expected pattern. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/logger | AI (phantom-deps): Same-org package; stable false positive for this org's monorepo pattern. | ai |
Versions (showing 46 of 46)
v20260719.2307.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260717.1322.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260717.1052.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260710.2240.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260709.1326.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260703.1338.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260627.1149.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.