@atomicservice/ascf-toolkit
ASCF toolkit for atomicservice
8
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
atomicservice
Keywords
atomicserviceloaderwebpack
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): HDC device executor communicates with local device IPs; expected for this toolkit. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Signing/crypto tooling legitimately uses hex encoding; no exfiltration pattern evident. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): CLI toolkit spawning processes is expected; consistent with ascf build tooling. | ai | |
| phantom-deps | phantom-dep:less | AI (phantom-deps): Peer/optional dep for webpack pipeline configuration; stable false positive. | ai | |
| phantom-deps | phantom-dep:sass | AI (phantom-deps): Peer/optional dep for webpack pipeline configuration; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): Peer/optional dep for webpack pipeline configuration; stable false positive. | ai | |
| phantom-deps | phantom-dep:log4js | AI (phantom-deps): Logging dep referenced via config convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Dev server dep; stable false positive for this toolkit. | ai | |
| phantom-deps | phantom-dep:less-loader | AI (phantom-deps): Webpack loader dep declared for downstream consumers; stable false positive. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI build toolkit; child_process use in version-check.js is expected for a tool that runs system commands. | ai | |
| phantom-deps | phantom-dep:babel-loader | AI (phantom-deps): Webpack loader dep declared for downstream consumers; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped dep loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Framework-scoped dep loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-runtime | AI (phantom-deps): Framework-scoped dep loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-class-properties | AI (phantom-deps): Framework-scoped dep loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-modules-commonjs | AI (phantom-deps): Framework-scoped dep loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:sass-loader | AI (phantom-deps): Webpack loader dep declared for downstream consumers; stable false positive. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): extract-loader.js is a webpack loader; dynamic require is inherent to loader design. | ai | |
| phantom-deps | phantom-dep:tar | AI (phantom-deps): Toolkit declares deps for downstream consumers; phantom-dep heuristic is a stable false positive here. | ai |