@tmlmobilidade/clickhouse
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Internal org package; missing description is a consistent pattern across this publisher's packages, not a malware indicator. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is consistent across this publisher's releases; low risk given org track record. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/utils | AI (phantom-deps): Same-org utility dep; likely re-exported or used indirectly within the org's build setup. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 20260322.1829.11 | 4 / 5 | |
| 20260322.1805.46 | 4 / 5 | |
| 20260322.1655.45 | 4 / 5 | |
| 20260320.2238.33 | 4 / 5 | |
| 20260320.1746.41 | 4 / 5 | |
| 20260320.1741.37 | 3 / 5 | |
| 20260316.1439.45 | 3 / 5 | |
| 20260316.1355.29 | 3 / 5 | |
| 20260309.2221.31 | 3 / 5 | |
| 20260309.1855.59 | 3 / 5 | |
| 20260308.1313.9 | 3 / 5 | |
| 20260306.1635.15 | 3 / 5 | |
| 20260305.1918.43 | 3 / 5 | |
| 20260305.1852.13 | 3 / 5 | |
| 20260305.1602.46 | 3 / 5 | |
| 20260302.1453.8 | 3 / 5 | |
| 20260302.1416.42 | 3 / 5 | |
| 20260226.1857.59 | 3 / 5 |
v20260322.1829.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20260322.1805.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260322.1655.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260320.2238.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260320.1746.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260320.1741.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260316.1439.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260316.1355.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260309.2221.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260309.1855.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260308.1313.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260306.1635.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260305.1918.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260305.1852.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260305.1602.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260302.1453.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260302.1416.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20260226.1857.59
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.