@cartella/core
Headless TypeScript core for Cartella — types, reducer, validation, migrations, layer-to-HTML
11
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
nyingmeh
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): 0.0.0 reflects early monorepo development; package.json is well-structured with a clear description, repo URL, and no malicious indicators. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Zod is a declared runtime dependency used for schema validation; phantom detection likely misses type-only or indirect imports in TypeScript libraries. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): False positive: @cartella/core is a scoped TypeScript core library for the Cartella project, not a typosquat of the cors middleware. The name similarity is coincidental (core vs cors). | ai |