← Home

kerberos

Kerberos library for Node.js

41
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

durrannbbeekendariakpdbx-node

Keywords

kerberossecurityauthentication

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher change from durran to dbx-node reflects MongoDB's organizational transition to a team account ([email protected]); repo remains under mongodb-js org with SLSA attestation. ai
maintainer-change maintainer-added AI (maintainer-change): dbx-node is the MongoDB Node.js driver team account; addition is consistent with the organizational rebrand and confirmed by SLSA provenance attestation. ai
install-scripts install-script:install AI (install-scripts): Standard native addon install pattern: prebuild-install fetches prebuilt NAPI binaries, falls back to node-gyp compile. Expected and documented for this MongoDB Kerberos C binding. ai
phantom-deps phantom-dep:node-addon-api AI (phantom-deps): node-addon-api is a build-time dependency for native addons; not directly imported in JS but used during compilation. Stable false positive for this package. ai
phantom-deps phantom-dep:prebuild-install AI (phantom-deps): prebuild-install is invoked via the install script, not imported in JS. Known implicit runtime/binary dependency pattern for native addons. ai

Versions (showing 41 of 41)

Version Deps Published
7.0.0 2 / 15
2.2.1 2 / 16
2.2.0 3 / 16
2.1.1 3 / 16
2.1.0 3 / 16
2.0.3 3 / 16
2.0.2 3 / 15
2.0.1 3 / 15
2.0.0 3 / 15
1.1.7 3 / 14
1.1.6 3 / 14
1.1.5 3 / 14
1.1.4 3 / 14
1.1.3 3 / 15
1.1.2 3 / 15
1.1.1 3 / 15
1.1.0 3 / 15
1.0.0 3 / 14
0.0.24 1 / 1
0.0.23 1 / 1
0.0.22 1 / 1
0.0.21 1 / 1
0.0.20 1 / 1
0.0.19 1 / 1
0.0.18 1 / 1
0.0.17 1 / 1
0.0.16 1 / 1
0.0.15 1 / 1
0.0.14 1 / 1
0.0.12 1 / 1
0.0.11 1 / 1
0.0.10 1 / 1
0.0.9 1 / 1
0.0.8 1 / 1
0.0.7 1 / 1
0.0.6 1 / 1
0.0.5 1 / 1
0.0.4 0 / 1
0.0.3 0 / 1
0.0.2 0 / 1
0.0.1 0 / 1

v7.0.0

2 findings
HIGH Package has 'install' script install-scripts

Script: prebuild-install --runtime napi || node-gyp rebuild

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.1

2 findings
HIGH Publisher changed: durran → dbx-node (on 2024-12-10) provenance

This version was published by a different npm account than previous versions on 2024-12-10. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

2 findings
HIGH Publisher changed: durran → dbx-node (on 2024-09-11) provenance

This version was published by a different npm account than previous versions on 2024-09-11. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.1

2 findings
HIGH Publisher changed: durran → dbx-node (on 2024-08-06) provenance

This version was published by a different npm account than previous versions on 2024-08-06. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.