← Home

@checkstack/healthcheck-backend

12
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

enyineer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@checkstack/incident-backend AI (phantom-deps): Same-org sibling package, false positive. ai
phantom-deps phantom-dep:@orpc/contract AI (phantom-deps): Config-referenced, not a real issue. ai
dependencies unvetted-dep:@checkstack/integration-backend AI (dependencies): Internal monorepo sibling package, not third-party. ai
publish-pattern new-deps-added AI (publish-pattern): Added deps are internal sibling + small stats lib, benign. ai
dependencies unvetted-dep:@checkstack/script-packages-backend AI (dependencies): First-party @checkstack sibling package. ai
dependencies unvetted-dep:@checkstack/sdk AI (dependencies): First-party @checkstack sibling package; unvetted only because newly added. ai
dependencies unvetted-dep:@checkstack/ai-common AI (dependencies): First-party @checkstack sibling package. ai
dependencies unvetted-dep:@checkstack/ai-backend AI (dependencies): First-party @checkstack sibling package. ai
dependencies unvetted-dep:@checkstack/automation-backend AI (dependencies): First-party @checkstack sibling package. ai
dependencies unvetted-dep:@checkstack/status-page-common AI (dependencies): First-party @checkstack sibling package. ai
dependencies unvetted-dep:@checkstack/status-page-backend AI (dependencies): First-party @checkstack sibling package. ai
dependencies unvetted-dep:tdigest AI (dependencies): tdigest is a well-known statistical library; stable false positive for this package. ai
npm-metadata no-description AI (npm-metadata): Internal monorepo package; missing description is consistent across all versions. ai
provenance no-provenance AI (provenance): Consistent across all @checkstack scoped packages; internal tooling pattern. ai
provenance missing-githead AI (provenance): Internal @checkstack monorepo package; publish environment change is plausible for a growing internal platform. ai
phantom-deps phantom-dep:@hono/zod-validator AI (phantom-deps): Same monorepo context; phantom-dep heuristic unreliable for workspace packages. ai
phantom-deps phantom-dep:hono AI (phantom-deps): Monorepo workspace package; hono likely imported transitively or via re-exports in sibling packages. ai
bogus-package bogus-package AI (bogus-package): Internal monorepo package; missing public metadata is expected for workspace-scoped packages. ai

Versions (showing 12 of 12)

Version Deps Published
1.17.0 35 / 9
1.13.0 34 / 9
1.11.0 34 / 9
1.6.1 32 / 9
1.2.0 24 / 9
1.1.0 23 / 9
0.16.4 20 / 8
0.10.6 17 / 8
0.10.2 16 / 10
0.8.3 16 / 10
0.4.1 14 / 8
0.4.0 14 / 8

v1.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.13.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: enyineer.

v1.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: enyineer.