@tmlmobilidade/fastify
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@tmlmobilidade/go-providers-auth | AI (dependencies): First-party internal monorepo package from same trusted publisher. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/go-interfaces-go-db | AI (dependencies): First-party same-org dependency, consistent with other @tmlmobilidade/* deps. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/go-interfaces-go-db | AI (phantom-deps): Same-org internal package, not directly imported by design of monorepo structure. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a first-party @tmlmobilidade scoped package from the same org; low risk for this publisher. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-frequency automated publishing is the norm for this org (~1.3 releases/day); rapid publish is expected, not suspicious. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): pino is a declared runtime dep used via config/logger setup; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): pino-pretty is a declared runtime dep used via config; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Publisher has 881 approved packages without provenance; stable pattern for this org. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Org monorepo package; consistently missing description across versions, not a malware indicator here. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/consts | AI (dependencies): Internal org dependency; consistent with this package's established publishing pattern. | ai | |
| dependencies | unvetted-dep:@fastify/one-line-logger | AI (dependencies): Official @fastify scoped package; low risk, stable dependency. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/interfaces | AI (dependencies): Internal org dependency; consistent with this package's established publishing pattern. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/utils | AI (dependencies): Internal org dependency; consistent with this package's established publishing pattern. | ai |
Versions (showing 38 of 38)
| Version | Deps | Published |
|---|---|---|
| 20260726.1208.42 | 9 / 6 | |
| 20260724.1738.47 | 9 / 6 | |
| 20260724.1726.44 | 9 / 6 | |
| 20260723.2334.13 | 9 / 6 | |
| 20260716.1737.51 | 9 / 6 | |
| 20260716.1727.27 | 9 / 6 | |
| 20260716.1659.40 | 9 / 6 | |
| 20260716.1615.24 | 9 / 6 | |
| 20260714.1333.48 | 10 / 6 | |
| 20260713.1740.11 | 10 / 6 | |
| 20260710.2210.9 | 10 / 6 | |
| 20260618.507.0 | 9 / 6 | |
| 20260617.1703.12 | 9 / 6 | |
| 20260616.2252.19 | 8 / 6 | |
| 20260616.229.43 | 8 / 6 | |
| 20260616.222.7 | 8 / 6 | |
| 20260611.1647.17 | 8 / 6 | |
| 20260609.1128.18 | 8 / 6 | |
| 20260607.1410.59 | 8 / 6 | |
| 20260607.1318.3 | 8 / 6 | |
| 20260605.149.34 | 8 / 6 | |
| 20260605.101.50 | 8 / 6 | |
| 20260603.40.36 | 8 / 6 | |
| 20260601.1808.3 | 8 / 6 | |
| 20260527.947.18 | 8 / 6 | |
| 20260526.1648.32 | 8 / 6 | |
| 20260525.1751.19 | 8 / 6 | |
| 20260525.1615.59 | 8 / 6 | |
| 20260518.901.35 | 8 / 6 | |
| 20260518.827.12 | 8 / 6 | |
| 20260509.331.19 | 8 / 6 | |
| 20260508.1103.58 | 8 / 6 | |
| 20260504.1217.59 | 8 / 6 | |
| 20260504.1029.41 | 8 / 6 | |
| 20260429.1713.40 | 8 / 6 | |
| 20260208.202.18 | 10 / 6 | |
| 20260206.1919.22 | 10 / 6 | |
| 20251202.1817.5 | 10 / 6 |
v20260726.1208.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260724.1738.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260724.1726.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260723.2334.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.1737.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.1727.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.1659.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.1615.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260714.1333.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260713.1740.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260710.2210.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.