@tmlmobilidade/utils
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): High-frequency automated CI/CD publishing is the established pattern for this package (1098 versions). | ai | |
| dependencies | unvetted-dep:@tmlmobilidade/dates | AI (dependencies): First-party sibling package from the same org; consistent with the rest of the @tmlmobilidade/* dependency pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are zod, luxon, and same-org @tmlmobilidade/* packages — all benign in context of this publisher. | ai | |
| provenance | no-provenance | AI (provenance): This org consistently publishes without Sigstore provenance; stable pattern across 1081 versions. | ai |
Versions (showing 51 of 151)
v20260724.1738.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260723.1550.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260719.2303.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260717.1321.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260716.1727.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20260709.1326.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.