@tmlmobilidade/import-gtfs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@tmlmobilidade/go-interfaces-go-db | AI (dependencies): Same-org internal dependency, consistent across versions. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/go-interfaces-godb | AI (dependencies): First-party org package renamed from prior sibling dep. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/go-interfaces-godb | AI (phantom-deps): Same-org internal package, monorepo import pattern. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/go-interfaces-go-db | AI (phantom-deps): Same-org internal package, wildcard version, not externally sourced. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are all same-org @tmlmobilidade scoped packages; not a third-party supply chain risk. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/dates | AI (dependencies): Same-org internal dependency; consistent with all other @tmlmobilidade/* deps in this package. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/connectors | AI (dependencies): Sibling package within the same @tmlmobilidade org; consistent with the rest of the ecosystem. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Package has 277 versions with frequent automated CI publishes; rapid publish is normal for this org. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/strings | AI (phantom-deps): Same org scope; likely used transitively or via re-export pattern, stable false positive. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/interfaces | AI (phantom-deps): Same org scope; type-only import pattern common in TypeScript packages, stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Org does not use Sigstore provenance; consistent across all 269 versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal org tooling package; missing description is consistent across the org's packages. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/sqlite | AI (dependencies): Internal sibling dep from same org; consistent pattern across all @tmlmobilidade packages. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/interfaces | AI (dependencies): Internal sibling dep from same org; consistent pattern across all @tmlmobilidade packages. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/logger | AI (dependencies): Internal sibling dep from same org; consistent pattern across all @tmlmobilidade packages. | ai |
Versions (showing 100 of 159)
v20260724.1738.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260724.1726.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260719.2316.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260717.1316.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.2128.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.1615.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260714.2327.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260714.1632.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260714.1333.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260713.2140.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260713.1740.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260713.1712.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260713.1622.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260713.1602.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260710.2210.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260709.1314.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260709.948.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260703.1331.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260519.2044.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.