@tmlmobilidade/geo
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@tmlmobilidade/go-types-vehicle-events | AI (dependencies): First-party sibling package within the same org monorepo. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Organizational package with clear repo and keywords; missing description is stable pattern. | ai | |
| provenance | no-provenance | AI (provenance): Provenance adoption is a future improvement; absence is not a malicious signal for this publisher. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-frequency automated releases are the norm for this org across hundreds of versions. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/go-types-public-info | AI (dependencies): Internal @tmlmobilidade scoped dependency; consistent with org's package ecosystem. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): TML org regularly adds internal @tmlmobilidade/* deps across its monorepo packages; pattern is stable and benign. | ai | |
| typosquat | typosquat.levenshtein:glob | AI (typosquat): Scoped org package for transit geo utilities; no resemblance to glob beyond edit distance. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Scoped org package for transit geo utilities; no resemblance to got beyond edit distance. | ai |
Versions (showing 100 of 366)
v20260726.1208.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260724.1738.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260723.1350.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260719.2316.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.1737.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260713.1602.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260710.2210.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260706.931.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260703.1331.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.