@aeriajs/core
Aeria core functionalities.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Monorepo package with 238 versions and ecosystem adoption; sparse metadata is typical for internal scoped packages. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped aeriajs monorepo package; 'core' vs 'cors' is coincidental Levenshtein proximity, not impersonation. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs a local dist script with || true fallback; consistent across 236 versions of this monorepo package. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 0.0.302 | 2 / 11 | |
| 0.0.300 | 2 / 11 | |
| 0.0.298 | 2 / 11 | |
| 0.0.297 | 2 / 11 | |
| 0.0.296 | 2 / 11 | |
| 0.0.295 | 2 / 11 | |
| 0.0.292 | 2 / 11 | |
| 0.0.291 | 2 / 11 | |
| 0.0.289 | 2 / 11 | |
| 0.0.288 | 2 / 11 | |
| 0.0.287 | 2 / 11 | |
| 0.0.285 | 2 / 11 | |
| 0.0.282 | 2 / 11 | |
| 0.0.277 | 2 / 11 | |
| 0.0.276 | 2 / 11 | |
| 0.0.274 | 2 / 11 | |
| 0.0.272 | 2 / 11 | |
| 0.0.270 | 2 / 11 | |
| 0.0.269 | 2 / 11 | |
| 0.0.268 | 2 / 11 | |
| 0.0.267 | 2 / 11 | |
| 0.0.265 | 2 / 11 | |
| 0.0.263 | 2 / 11 | |
| 0.0.262 | 2 / 11 | |
| 0.0.260 | 2 / 11 | |
| 0.0.258 | 2 / 11 | |
| 0.0.254 | 2 / 11 |
v0.0.302
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.300
3 findingsScript: node dist/__scripts__/postinstall.js || true
Package name '@aeriajs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.298
3 findingsScript: node dist/__scripts__/postinstall.js || true
Package name '@aeriajs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.297
3 findingsScript: node dist/__scripts__/postinstall.js || true
Package name '@aeriajs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.296
3 findingsScript: node dist/__scripts__/postinstall.js || true
Package name '@aeriajs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.295
3 findingsScript: node dist/__scripts__/postinstall.js || true
Package name '@aeriajs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.292
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.291
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.289
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.288
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.287
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.285
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.282
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.277
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.276
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.274
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.272
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.270
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.269
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.268
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.267
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.265
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.263
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.262
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.260
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.258
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.254
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.