@be-link/ecommerce-user-service-node-sdk
12
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
8848top-devhanguodongwangml0310
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:tsoa | AI (dependencies): tsoa is a well-established TypeScript REST/OpenAPI framework; its use here is consistent with the package's swagger/build scripts. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is tsoa, a legitimate build/codegen tool; not a suspicious or novel package. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Private RFC-1918 IP (192.168.56.220) used as internal NAT host; not a public exfiltration endpoint. | ai | |
| phantom-deps | phantom-dep:safe-stable-stringify | AI (phantom-deps): safe-stable-stringify is declared in package.json dependencies; phantom-dep heuristic false positive. | ai |