@checkstack/notification-backend
30
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
enyineer
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@checkstack/automation-backend | AI (dependencies): Same org scope (@checkstack); consistent with the package's internal ecosystem pattern once the dep itself is vetted. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @orpc/server is a legitimate RPC library; addition is consistent with this org's backend package evolution. | ai | |
| dependencies | unvetted-dep:@orpc/server | AI (dependencies): @orpc/server is a legitimate open-source RPC library; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:@checkstack/cache-utils | AI (dependencies): Same-org @checkstack scoped package; consistent with the ecosystem pattern of this package. | ai | |
| dependencies | unvetted-dep:@checkstack/cache-api | AI (dependencies): Same-org @checkstack scoped package; consistent with the ecosystem pattern of this package. | ai | |
| dependencies | unvetted-dep:@checkstack/auth-backend | AI (dependencies): Monorepo workspace sibling; not an external supply-chain risk. | ai | |
| dependencies | unvetted-dep:@checkstack/queue-api | AI (dependencies): Monorepo workspace sibling; not an external supply-chain risk. | ai | |
| dependencies | unvetted-dep:@checkstack/auth-common | AI (dependencies): Monorepo workspace sibling; not an external supply-chain risk. | ai | |
| dependencies | unvetted-dep:@checkstack/backend-api | AI (dependencies): Monorepo workspace sibling; not an external supply-chain risk. | ai | |
| dependencies | unvetted-dep:@checkstack/notification-common | AI (dependencies): Monorepo workspace sibling; not an external supply-chain risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal @checkstack org package; sparse metadata is consistent across the whole org's packages. | ai | |
| phantom-deps | phantom-dep:@checkstack/queue-api | AI (phantom-deps): Same-org scoped dep; phantom-dep heuristic unreliable for monorepo-style packages. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across @checkstack org; not a malware signal here. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal tooling package; missing description is stable across this org's packages. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 1.5.16 | 14 / 7 | |
| 1.4.2 | 13 / 7 | |
| 1.3.0 | 12 / 7 | |
| 1.2.0 | 12 / 7 | |
| 1.1.0 | 12 / 7 | |
| 1.0.5 | 12 / 7 | |
| 1.0.4 | 12 / 7 | |
| 1.0.3 | 12 / 7 | |
| 1.0.2 | 12 / 7 | |
| 1.0.1 | 12 / 7 | |
| 1.0.0 | 12 / 7 | |
| 0.2.1 | 12 / 6 | |
| 0.2.0 | 12 / 6 | |
| 0.1.23 | 10 / 6 | |
| 0.1.21 | 10 / 6 | |
| 0.1.20 | 10 / 6 | |
| 0.1.16 | 10 / 6 | |
| 0.1.13 | 9 / 8 | |
| 0.1.8 | 9 / 8 | |
| 0.1.7 | 9 / 8 | |
| 0.1.6 | 9 / 8 | |
| 0.1.5 | 9 / 8 | |
| 0.1.4 | 9 / 8 | |
| 0.1.3 | 9 / 8 | |
| 0.1.2 | 9 / 8 | |
| 0.1.1 | 9 / 8 | |
| 0.1.0 | 9 / 8 | |
| 0.0.4 | 9 / 8 | |
| 0.0.3 | 9 / 8 | |
| 0.0.2 | 9 / 8 |