← Home

@checkstack/satellite

47
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

enyineer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@checkstack/tracestream-common AI (dependencies): Same-org internal dependency, monorepo growth. ai
dependencies unvetted-dep:@checkstack/k8s-events-common AI (dependencies): Same-org internal dependency, monorepo growth. ai
dependencies unvetted-dep:@checkstack/telemetry-common AI (dependencies): Same-org internal dependency, monorepo growth. ai
npm-metadata no-description AI (npm-metadata): Established package with 45 versions; missing description is metadata gap, not malware indicator. ai
provenance no-provenance AI (provenance): Provenance absence is improvement opportunity, not security blocker for this package. ai
dependencies unvetted-dep:@checkstack/otlp-wire AI (dependencies): Same-org internal monorepo dependency, not third-party. ai
dependencies unvetted-dep:@checkstack/ingest-utils AI (dependencies): Same-org internal monorepo dependency, not third-party. ai
dependencies unvetted-dep:@checkstack/logstream-common AI (dependencies): Same-org internal monorepo dependency, not third-party. ai
dependencies unvetted-dep:@checkstack/metricstream-common AI (dependencies): Same-org internal monorepo dependency, not third-party. ai
phantom-deps phantom-dep:@checkstack/otlp-wire AI (phantom-deps): Same-org scoped package, false positive on import detection. ai
phantom-deps phantom-dep:@checkstack/secrets-common AI (phantom-deps): Same org scope, likely type-only or re-exported usage. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Used indirectly via config/schema, common false positive. ai
dependencies unvetted-dep:@checkstack/script-packages-backend AI (dependencies): First-party @checkstack monorepo dependency, not an external unvetted package. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode is part of script-package payload deserialization, no network exfil. ai
bogus-package bogus-package AI (bogus-package): Internal scoped org package; missing metadata is expected for private tooling, not a spam/malware indicator. ai

Versions (showing 47 of 47)

Version Deps Published
0.8.0 14 / 4
0.7.2 11 / 4
0.7.0 11 / 4
0.6.6 7 / 4
0.6.5 7 / 4
0.6.4 7 / 4
0.6.3 7 / 4
0.6.2 7 / 4
0.6.1 7 / 4
0.6.0 7 / 4
0.5.21 4 / 4
0.5.20 4 / 4
0.5.19 4 / 4
0.5.18 4 / 4
0.5.17 4 / 4
0.5.16 4 / 4
0.5.15 4 / 4
0.5.14 4 / 4
0.5.13 4 / 4
0.5.12 4 / 4
0.5.11 4 / 4
0.5.10 4 / 4
0.5.9 4 / 4
0.5.8 4 / 4
0.5.7 4 / 4
0.5.6 4 / 4
0.5.5 4 / 4
0.5.4 4 / 4
0.5.3 4 / 4
0.5.2 4 / 4
0.5.1 4 / 4
0.5.0 4 / 4
0.4.1 4 / 4
0.4.0 4 / 4
0.3.0 3 / 4
0.2.11 3 / 4
0.2.10 3 / 4
0.2.9 3 / 4
0.2.8 3 / 4
0.2.7 3 / 4
0.2.6 3 / 4
0.2.5 3 / 4
0.2.4 3 / 4
0.2.3 3 / 4
0.2.2 3 / 4
0.2.1 3 / 4
0.2.0 3 / 4

v0.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.