@xyo-network/account
10
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
atrouwjoelbcarterrphansen91jordantrouwjonesmac
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Large monorepo with frequent releases; gitHead absence in one version is not indicative of malicious activity given publisher track record. | ai | |
| provenance | publisher-changed | AI (provenance): xyo org account with 450 approved packages; consistent with org-level publisher consolidation for this package family. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established XYO Network SDK package with 1400+ days history; sparse README is a style choice, not spam. | ai | |
| provenance | no-provenance | AI (provenance): Long-established XYO Network package; provenance absence is consistent across all versions and not a security concern here. | ai |