@514labs/moose-lib
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-peer-dep:ts-patch | AI (dependencies): Peer dependency in optional peer deps; already marked as accepted risk. | ai | |
| provenance | publisher-changed | AI (provenance): 514labs transitioned from 514bot to GitHub Actions for publishing, confirmed by SLSA provenance attestation. This is a legitimate CI/CD migration, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): luciofranco appears to be a legitimate team member addition within the 514labs org, consistent with the GitHub Actions publishing transition and SLSA attestation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @514labs/kafka-javascript is a same-org scoped package, not a third-party injection. Consistent with internal tooling expansion. | ai | |
| provenance | no-provenance | AI (provenance): Provenance attestation is missing but common across npm ecosystem; not a disqualifier for established packages with clean publisher track records. | ai | |
| dependencies | unvetted-dep:@confluentinc/kafka-javascript | AI (dependencies): @confluentinc/kafka-javascript is the official Confluent Kafka JS client; legitimate dependency for a data engineering framework like moose-lib. | ai | |
| phantom-deps | phantom-dep:tsconfig-paths | AI (phantom-deps): tsconfig-paths is used at runtime via ts-node for TypeScript path resolution; not directly imported in source but legitimately needed. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Package is 695 days old with 4213 versions and a legitimate data engineering framework purpose; missing metadata is a hygiene issue, not a spam/malware indicator. | ai | |
| dependencies | unvetted-dep:@514labs/kafka-javascript | AI (dependencies): Publisher's own patched fork of kafka-javascript; consistent with the package's data infrastructure focus. | ai | |
| dependencies | unvetted-dep:@kafkajs/confluent-schema-registry | AI (dependencies): Well-known Confluent Schema Registry client maintained by the KafkaJS org. Legitimate dependency for Kafka-based data pipelines. | ai | |
| dependencies | unvetted-dep:@temporalio/client | AI (dependencies): Temporal.io SDK is a well-known, legitimate workflow orchestration library from Temporal Technologies. Stable dependency for this data infrastructure package. | ai | |
| dependencies | unvetted-dep:@temporalio/common | AI (dependencies): Temporal.io SDK common package from Temporal Technologies. Legitimate and stable dependency. | ai | |
| dependencies | unvetted-dep:@temporalio/worker | AI (dependencies): Temporal.io SDK worker package from Temporal Technologies. Legitimate and stable dependency. | ai | |
| dependencies | unvetted-dep:@temporalio/activity | AI (dependencies): Temporal.io SDK activity package from Temporal Technologies. Legitimate and stable dependency. | ai | |
| dependencies | unvetted-dep:@temporalio/workflow | AI (dependencies): Temporal.io SDK workflow package from Temporal Technologies. Legitimate and stable dependency. | ai | |
| dependencies | unvetted-dep:@clickhouse/client-web | AI (dependencies): Official ClickHouse browser-compatible client from ClickHouse Inc. Legitimate dependency for a data infrastructure library. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Automated CI/CD publishing pipeline for an established package; missing description is a cosmetic issue, not a security signal. | ai | |
| phantom-deps | phantom-dep:@clickhouse/client-web | AI (phantom-deps): ClickHouse web client declared for browser-compatible export path; phantom-dep flag is expected given the conditional export structure. | ai | |
| phantom-deps | phantom-dep:@temporalio/common | AI (phantom-deps): Temporal common types package declared for type-level usage; phantom-dep flag is expected for type/config dependencies. | ai | |
| phantom-deps | phantom-dep:fastq | AI (phantom-deps): fastq is a legitimate declared dependency used transitively; phantom-dep flag is a structural note, not a security concern for this package. | ai |
Versions (showing 100 of 576)
| Version | Deps | Published |
|---|---|---|
| 0.6.232 | 17 / 10 | |
| 0.6.231 | 17 / 10 | |
| 0.6.230 | 17 / 10 | |
| 0.6.229 | 17 / 10 | |
| 0.6.228 | 17 / 10 | |
| 0.6.227 | 17 / 10 | |
| 0.6.226 | 17 / 10 | |
| 0.6.225 | 17 / 10 | |
| 0.6.224 | 17 / 10 | |
| 0.6.223 | 17 / 10 | |
| 0.6.222 | 17 / 10 | |
| 0.6.221 | 17 / 10 | |
| 0.6.220 | 17 / 10 | |
| 0.6.219 | 17 / 10 | |
| 0.6.218 | 17 / 10 | |
| 0.6.217 | 17 / 10 | |
| 0.6.216 | 17 / 10 | |
| 0.6.215 | 17 / 10 | |
| 0.6.214 | 17 / 10 | |
| 0.6.213 | 17 / 10 | |
| 0.6.212 | 17 / 10 | |
| 0.6.211 | 17 / 10 | |
| 0.6.210 | 17 / 10 | |
| 0.6.209 | 17 / 10 | |
| 0.6.208 | 17 / 10 | |
| 0.6.207 | 17 / 10 | |
| 0.6.206 | 17 / 10 | |
| 0.6.205 | 17 / 10 | |
| 0.6.204 | 17 / 10 | |
| 0.6.203 | 17 / 10 | |
| 0.6.202 | 17 / 10 | |
| 0.6.201 | 17 / 10 | |
| 0.6.200 | 17 / 10 | |
| 0.6.199 | 17 / 10 | |
| 0.6.198 | 17 / 10 | |
| 0.6.197 | 17 / 10 | |
| 0.6.196 | 17 / 10 | |
| 0.6.195 | 17 / 10 | |
| 0.6.194 | 17 / 10 | |
| 0.6.193 | 17 / 10 | |
| 0.6.192 | 17 / 10 | |
| 0.6.191 | 17 / 10 | |
| 0.6.190 | 17 / 10 | |
| 0.6.189 | 17 / 10 | |
| 0.6.188 | 17 / 10 | |
| 0.6.187 | 17 / 10 | |
| 0.6.186 | 17 / 10 | |
| 0.6.185 | 17 / 10 | |
| 0.6.184 | 17 / 10 | |
| 0.6.183 | 17 / 10 | |
| 0.6.182 | 17 / 10 | |
| 0.6.181 | 17 / 10 | |
| 0.6.180 | 17 / 10 | |
| 0.6.179 | 17 / 10 | |
| 0.6.178 | 17 / 10 | |
| 0.6.177 | 17 / 10 | |
| 0.6.176 | 17 / 10 | |
| 0.6.175 | 17 / 10 | |
| 0.6.174 | 17 / 10 | |
| 0.6.173 | 17 / 10 | |
| 0.6.172 | 17 / 10 | |
| 0.6.171 | 17 / 10 | |
| 0.6.170 | 17 / 10 | |
| 0.6.169 | 17 / 10 | |
| 0.6.168 | 17 / 10 | |
| 0.6.167 | 17 / 10 | |
| 0.6.166 | 17 / 10 | |
| 0.6.165 | 17 / 10 | |
| 0.6.164 | 17 / 10 | |
| 0.6.163 | 17 / 10 | |
| 0.6.162 | 17 / 10 | |
| 0.6.161 | 17 / 10 | |
| 0.6.160 | 17 / 10 | |
| 0.6.159 | 17 / 10 | |
| 0.6.158 | 18 / 10 | |
| 0.6.157 | 18 / 10 | |
| 0.6.156 | 18 / 10 | |
| 0.6.155 | 18 / 10 | |
| 0.6.154 | 18 / 10 | |
| 0.6.153 | 18 / 10 | |
| 0.6.152 | 18 / 10 | |
| 0.6.151 | 18 / 10 | |
| 0.6.150 | 18 / 10 | |
| 0.6.149 | 18 / 10 | |
| 0.6.148 | 18 / 10 | |
| 0.6.147 | 18 / 10 | |
| 0.6.146 | 18 / 10 | |
| 0.6.145 | 18 / 10 | |
| 0.6.144 | 18 / 10 | |
| 0.6.143 | 18 / 10 | |
| 0.6.142 | 18 / 10 | |
| 0.6.141 | 18 / 10 | |
| 0.6.140 | 18 / 10 | |
| 0.6.139 | 18 / 10 | |
| 0.6.138 | 18 / 10 | |
| 0.6.137 | 18 / 10 | |
| 0.6.136 | 18 / 10 | |
| 0.6.135 | 18 / 10 | |
| 0.6.134 | 18 / 10 | |
| 0.6.133 | 18 / 10 |
v0.6.232
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.231
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.230
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.229
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.228
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.227
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.226
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.225
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.224
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.223
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.222
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.221
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.220
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.219
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.218
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.217
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.216
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.215
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.214
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.213
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.212
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.211
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.210
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.209
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.208
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.207
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.206
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.205
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.204
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.203
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.202
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.201
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.200
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.199
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.198
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.197
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.196
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.195
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.194
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.193
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.192
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.190
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.189
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.188
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.187
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.185
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.184
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.183
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.182
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.181
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.180
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.179
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.178
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.177
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.176
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.175
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.174
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.173
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.172
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.171
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.170
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.169
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.168
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.167
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.166
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.164
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.162
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.161
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.160
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.159
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.158
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.157
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.156
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.154
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.153
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.152
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.150
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.149
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.148
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.147
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.146
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.145
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.144
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.143
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.142
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.141
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.140
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.139
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.138
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.137
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.136
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.135
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.134
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.133
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.