@tmlmobilidade/import-gtfs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are all same-org @tmlmobilidade scoped packages; not a third-party supply chain risk. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/dates | AI (dependencies): Same-org internal dependency; consistent with all other @tmlmobilidade/* deps in this package. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/connectors | AI (dependencies): Sibling package within the same @tmlmobilidade org; consistent with the rest of the ecosystem. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Package has 277 versions with frequent automated CI publishes; rapid publish is normal for this org. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/strings | AI (phantom-deps): Same org scope; likely used transitively or via re-export pattern, stable false positive. | ai | |
| phantom-deps | phantom-dep:@tmlmobilidade/interfaces | AI (phantom-deps): Same org scope; type-only import pattern common in TypeScript packages, stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Org does not use Sigstore provenance; consistent across all 269 versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal org tooling package; missing description is consistent across the org's packages. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/sqlite | AI (dependencies): Internal sibling dep from same org; consistent pattern across all @tmlmobilidade packages. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/interfaces | AI (dependencies): Internal sibling dep from same org; consistent pattern across all @tmlmobilidade packages. | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/logger | AI (dependencies): Internal sibling dep from same org; consistent pattern across all @tmlmobilidade packages. | ai |
Versions (showing 4 of 104)
| Version | Deps | Published |
|---|---|---|
| 20251204.1130.15 | 6 / 6 | |
| 20251202.1821.43 | 6 / 6 | |
| 20251202.1817.5 | 6 / 6 | |
| 20251103.1255.55 | 3 / 8 |
v20251204.1130.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20251202.1821.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20251202.1817.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20251103.1255.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.