mongoose
Mongoose MongoDB ODM
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | regressed-provenance | AI (provenance): Known maintainer manual publish of 7.x backport; not compromise for this package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Build/tarball script only; not runtime code. | ai | |
| source-diff | encoded-string-file:dist/browser.umd.js | AI (source-diff): Standard webpack UMD browser bundle; stable across versions. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA provenance; legitimate for this package. | ai | |
| provenance | slsa-provenance | AI (provenance): SLSA provenance attestation confirms CI/CD publishing integrity. | ai | |
| source-diff | net-exec-file:dist/browser.umd.js | AI (source-diff): Webpack UMD browser bundle declared in package.json browser field; stable for this package. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): UUID hex parsing in cast/uuid.js; standard MongoDB ODM functionality. | ai | |
| dependencies | unvetted-dep:mpath | AI (dependencies): mpath is a mongoose ecosystem package maintained by the mongoose team; stable false positive for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Buffer.from(value.$binary, 'base64') is standard MongoDB BSON extended JSON deserialization for Binary types; not malicious payload handling. | ai | |
| dependencies | unvetted-dep:mongodb | AI (dependencies): mongodb is the official MongoDB Node.js driver; a core, well-known dependency of mongoose; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:mquery | AI (dependencies): mquery is a mongoose ecosystem query builder maintained by the mongoose team; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:kareem | AI (dependencies): kareem is a mongoose ecosystem package (middleware hooks) maintained by the mongoose team; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:sift | AI (dependencies): sift is a long-standing, well-known dependency of mongoose for query filtering; stable false positive for this package. | ai |
Versions (showing 53 of 53)
| Version | Deps | Published |
|---|---|---|
| 9.8.1 | 7 / 37 | |
| 9.8.0 | 7 / 37 | |
| 9.7.4 | 7 / 37 | |
| 9.7.3 | 7 / 37 | |
| 9.7.2 | 6 / 37 | |
| 9.7.1 | 6 / 37 | |
| 9.7.0 | 6 / 36 | |
| 9.6.3 | 6 / 36 | |
| 9.6.2 | 6 / 36 | |
| 9.6.1 | 6 / 36 | |
| 9.6.0 | 6 / 36 | |
| 9.5.0 | 6 / 36 | |
| 9.4.1 | 6 / 36 | |
| 9.4.0 | 6 / 36 | |
| 9.3.3 | 6 / 36 | |
| 9.3.2 | 6 / 36 | |
| 9.3.1 | 6 / 36 | |
| 9.3.0 | 6 / 36 | |
| 9.2.4 | 6 / 36 | |
| 9.2.3 | 6 / 33 | |
| 9.2.2 | 6 / 33 | |
| 9.2.1 | 6 / 32 | |
| 9.2.0 | 6 / 32 | |
| 9.1.6 | 6 / 33 | |
| 9.1.5 | 6 / 33 | |
| 9.1.4 | 6 / 33 | |
| 9.1.3 | 6 / 33 | |
| 9.1.2 | 6 / 33 | |
| 9.1.1 | 6 / 33 | |
| 9.1.0 | 6 / 33 | |
| 9.0.2 | 6 / 33 | |
| 9.0.1 | 6 / 33 | |
| 9.0.0 | 6 / 33 | |
| 8.24.1 | 7 / 42 | |
| 8.24.0 | 7 / 42 | |
| 8.23.1 | 7 / 42 | |
| 8.23.0 | 7 / 42 | |
| 8.22.1 | 7 / 42 | |
| 8.22.0 | 7 / 42 | |
| 8.21.1 | 7 / 42 | |
| 8.21.0 | 7 / 42 | |
| 8.20.4 | 7 / 42 | |
| 8.20.3 | 7 / 42 | |
| 8.20.2 | 7 / 42 | |
| 8.20.1 | 7 / 42 | |
| 8.20.0 | 7 / 42 | |
| 8.19.4 | 7 / 42 | |
| 8.19.3 | 7 / 42 | |
| 7.8.11 | 7 / 41 | |
| 7.8.10 | 7 / 41 | |
| 7.8.9 | 7 / 41 | |
| 7.8.8 | 7 / 41 | |
| 6.13.10 | 7 / 43 |
v9.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.8.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vkarpov15) on 2026-07-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v9.7.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.8.11
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account (vkarpov15) than the most recent previously approved version (GitHub Actions) on 2026-07-06, but vkarpov15 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.