@casual-simulation/aux-records
Helpers and managers used by the CasualOS records system.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@casual-simulation/fast-json-stable-stringify | AI (dependencies): Same-org dependency from Casual Simulation; consistent with package's ecosystem. | ai | |
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation which supersedes gitHead as a supply chain integrity signal. | ai | |
| dependencies | unvetted-dep:@casual-simulation/crypto | AI (dependencies): Same-org dependency from Casual Simulation; consistent with package's ecosystem. | ai | |
| dependencies | unvetted-dep:@casual-simulation/timesync | AI (dependencies): Same-org dependency from Casual Simulation; consistent with package's ecosystem. | ai | |
| dependencies | unvetted-dep:@casual-simulation/rate-limit-redis | AI (dependencies): Same-org dependency from Casual Simulation; consistent with package's ecosystem. | ai | |
| phantom-deps | phantom-dep:preact-render-to-string | AI (phantom-deps): Config-file reference only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/resources | AI (phantom-deps): Config-file reference only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@casual-simulation/timesync | AI (phantom-deps): Same-org scoped package; indirect usage pattern is stable for this monorepo. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard Proxy trap pattern using Reflect.get(); not obfuscation. Stable for this package. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 4.2.4 | 32 / 0 | |
| 4.2.3 | 32 / 0 | |
| 3.10.4 | 32 / 0 | |
| 3.10.3 | 32 / 0 | |
| 3.10.2 | 32 / 0 | |
| 3.8.1 | 29 / 0 |
v4.2.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.