@accounter/server
2
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
gilgardosh
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Major version bump; size increase consistent with added modules and generated types. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decoding email attachment content (base64 is standard email encoding) — benign. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decoding an encryption key in a credential encryption helper — legitimate crypto usage. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version bump with many new features; large file count expected. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from manual publish to GitHub Actions CI/CD with SLSA attestation — expected for this repo. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread is in test files saving/restoring process.env — standard test pattern, not exfil. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): 0.0.0 is a common monorepo internal versioning convention; 3416 published versions confirm this is not a throwaway package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal monorepo server package; missing metadata is expected for private/internal packages. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped @accounter org package; not a typosquat of semver. 3416 versions and 784-day history confirm legitimacy. | ai |