@tmlmobilidade/repo-version
A CLI tool to bump the version of a NodeJS package.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@tmlmobilidade/dates | AI (dependencies): First-party org dependency (@tmlmobilidade); stable pattern across this package's many versions. | ai | |
| license | copyleft-license:AGPL-3.0-or-later | AI (license): Package is intentionally AGPL-3.0; stable license choice for this org's tooling. | ai | |
| provenance | publisher-changed-known-maintainer | AI (provenance): Known maintainer rotation within the same org; stable pattern for this package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): 246 versions in registry indicates automated versioning pipeline; rapid publishes are expected for this package. | ai | |
| provenance | no-provenance | AI (provenance): Consistent across all 232 versions from this publisher; not a security concern for this package. | ai |
Versions (showing 51 of 204)
v20260719.2307.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260709.1326.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260703.1330.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260627.1149.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.