← Home

@blocklet/uploader-server

blocklet upload server

51
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

wangshijungxw

Keywords

blockletuploaderserver

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@abtnode/cron AI (dependencies): Same org (ArcBlock/ABTNode) as the package publisher; internal dependency. ai
dependencies unvetted-dep:@tus/server AI (dependencies): Well-known tus protocol server library; legitimate dependency for an uploader package. ai
dependencies unvetted-dep:@tus/file-store AI (dependencies): Official tus file-store companion; legitimate for an uploader server. ai
dependencies unvetted-dep:@uppy/companion AI (dependencies): Official Uppy companion server; expected dependency for an uploader package. ai
dependencies unvetted-dep:exif-be-gone AI (dependencies): Known EXIF stripping library; appropriate for an image uploader server. ai
publish-pattern dormant-publish AI (publish-pattern): Publisher has strong track record (62 approved, 0 rejected); version diff shows no material changes, reducing takeover risk. ai
provenance no-provenance AI (provenance): No provenance is common (~88% of npm); no other risk signals elevate this. ai
phantom-deps phantom-dep:@blocklet/constant AI (phantom-deps): Same org scope; likely used indirectly via re-exports. Stable false positive for this package. ai
phantom-deps phantom-dep:ufo AI (phantom-deps): ufo is declared as a dependency and used transitively; phantom-dep heuristic false positive for this package. ai

Versions (showing 51 of 80)

View all versions
Version Deps Published
0.3.19 18 / 11
0.3.16 18 / 11
0.3.15 18 / 11
0.3.14 18 / 11
0.3.13 18 / 11
0.3.11 18 / 11
0.3.9 18 / 11
0.3.8 18 / 11
0.3.7 18 / 11
0.3.5 18 / 11
0.3.4 18 / 11
0.3.3 18 / 11
0.3.2 18 / 11
0.3.1 18 / 11
0.3.0 18 / 11
0.2.15 18 / 11
0.2.14 18 / 11
0.2.13 18 / 11
0.2.12 18 / 11
0.2.11 18 / 11
0.2.10 18 / 11
0.2.9 18 / 11
0.2.8 18 / 11
0.2.7 18 / 11
0.2.6 18 / 11
0.2.5 18 / 11
0.2.4 18 / 11
0.2.3 18 / 11
0.2.2 18 / 11
0.2.1 18 / 11
0.2.0 18 / 11
0.1.102 18 / 11
0.1.96 17 / 11
0.1.95 17 / 11
0.1.94 17 / 11
0.1.93 17 / 11
0.1.92 17 / 11
0.1.91 16 / 11
0.1.90 15 / 11
0.1.89 15 / 11
0.1.88 15 / 11
0.1.87 15 / 11
0.1.86 15 / 11
0.1.85 15 / 11
0.1.84 15 / 11
0.1.83 15 / 11
0.1.82 15 / 11
0.1.81 15 / 11
0.1.80 15 / 10
0.1.79 15 / 10
0.1.78 15 / 10

v0.1.95

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.94

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.93

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.92

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.91

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.90

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.88

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.87

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.86

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.85

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.84

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.83

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.82

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.81

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.80

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.79

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.78

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.