← Home

@builderbot/provider-sherpa

Provider Sherpa for BuilderBot - WhatsApp integration using Whaileys

1
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

leifermendez

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:sharp AI (phantom-deps): Known implicit/binary dependency pattern for image processing in WhatsApp providers. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard TypeScript runtime helper, commonly declared but not directly imported. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): TypeScript declared as dep for type-checking; not directly imported at runtime. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): Rollup referenced in build config; stable false positive for this build-tool pattern. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Utility dep used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:fluent-ffmpeg AI (phantom-deps): Media processing dep used indirectly via ffmpeg installer; stable false positive. ai
phantom-deps phantom-dep:jimp AI (phantom-deps): Image processing dep referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:qrcode-terminal AI (phantom-deps): QR code dep used indirectly in WhatsApp auth flow; stable false positive. ai
phantom-deps phantom-dep:@adiwajshing/keyed-db AI (phantom-deps): Baileys/Whaileys transitive dep declared explicitly; stable false positive. ai
phantom-deps phantom-dep:@ffmpeg-installer/ffmpeg AI (phantom-deps): Binary installer dep used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:@types/polka AI (phantom-deps): Type definitions loaded by convention; stable false positive. ai

Versions (showing 1 of 1)

Version Deps Published
1.4.1 13 / 26

v1.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.