← Home

fellow

Fellow is a package for creating people that can be unified by their shared values via a singleton list on the class

51
Versions
Artistic-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

bevryme

Keywords

authorauthorsbrowsercontributorcontributorsdenodeno-editiondeno-entrydenolandes2017es2022export-defaultfellowgithub usermaintainermaintainersmodulenodepeoplepersontypedtypestypescriptuser

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:kava AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:surge AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:eslint AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:typedoc AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:projectz AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:valid-module AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:assert-helpers AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:valid-directory AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:make-deno-edition AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:eslint-config-bevry AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:eslint-plugin-babel AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:eslint-plugin-prettier AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:@bevry/update-contributors AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): Dev tooling duplicated into dependencies field; not directly imported at runtime. Stable false positive for bevry packages. ai

Versions (showing 51 of 53)

View all versions
Version Deps Published
7.4.0 2 / 17
7.3.0 2 / 17
7.2.1 2 / 17
7.2.0 2 / 17
7.1.2 2 / 17
7.1.1 2 / 17
7.1.0 2 / 17
7.0.4 2 / 17
7.0.3 2 / 17
7.0.2 1 / 17
7.0.1 1 / 17
7.0.0 1 / 18
6.25.0 0 / 19
6.24.0 0 / 18
6.23.0 0 / 18
6.22.0 0 / 18
6.21.0 0 / 18
6.20.0 0 / 18
6.18.0 0 / 18
6.17.0 0 / 18
6.16.0 0 / 18
6.15.0 0 / 18
6.14.0 0 / 18
6.13.0 1 / 18
6.12.0 18 / 18
6.11.0 0 / 18
6.10.0 0 / 18
6.9.0 0 / 17
6.8.0 0 / 17
6.7.0 0 / 17
6.6.0 0 / 17
6.5.0 0 / 17
6.4.0 0 / 16
6.3.0 0 / 16
6.2.0 0 / 16
6.1.0 0 / 16
6.0.0 0 / 16
5.0.0 0 / 16
4.0.0 0 / 17
3.3.0 0 / 17
3.2.0 0 / 17
3.1.0 0 / 17
3.0.0 0 / 17
2.6.0 1 / 17
2.5.0 1 / 17
2.4.0 1 / 17
2.3.0 1 / 9
2.2.0 1 / 9
2.1.0 1 / 8
2.0.0 1 / 8
1.2.0 0 / 8

v7.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.