← Home

mongodb-client-encryption

2
Versions
License
Yes
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

dariakpdbx-node

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from human npm account to GitHub Actions CI/CD; consistent with mongodb-js org practices. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer list cleanup during CI/CD migration; package remains under mongodb-js org. ai
publish-pattern dormant-publish AI (publish-pattern): Gap between major versions is normal for this package's release cadence. ai
install-scripts install-script:install AI (install-scripts): Standard prebuild-install/node-gyp pattern for native NAPI addon; stable for this package. ai
bogus-package bogus-package AI (bogus-package): Official MongoDB package; mass-production signal reflects the mongodb-js org's many packages. ai
phantom-deps phantom-dep:node-addon-api AI (phantom-deps): node-addon-api is consumed by node-gyp at build time via binding.gyp, not via JS import. ai
phantom-deps phantom-dep:prebuild-install AI (phantom-deps): prebuild-install is invoked from the install script, not imported in JS. ai

Versions (showing 2 of 2)

Version Deps Published
7.1.0 2 / 28
7.0.0 2 / 28

v7.1.0

2 findings
HIGH Publisher changed: dbx-node → GitHub Actions (on 2026-06-25) provenance

This version was published by a different npm account than previous versions on 2026-06-25. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.