@contractspec/app.registry-server
Website: https://contractspec.io
16
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
farzim
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Scoped package with repo URL; missing description is cosmetic, not a malware signal. | ai | |
| provenance | no-provenance | AI (provenance): Only ~12% of npm packages have provenance; not a disqualifier for established packages. | ai | |
| phantom-deps | phantom-dep:@contractspec/lib.contracts | AI (phantom-deps): Same-org internal dependency; expected pattern for monorepo packages. | ai | |
| dependencies | unvetted-dep:@elysiajs/server-timing | AI (dependencies): Legitimate Elysia framework plugin; stable dependency for this package across versions. | ai | |
| phantom-deps | phantom-dep:elysia | AI (phantom-deps): Elysia is a framework likely used via config/type imports; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@contractspec/lib.contracts-spec | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@elysiajs/cors | AI (phantom-deps): Elysia plugin referenced in config; stable false positive for this monorepo app package. | ai | |
| phantom-deps | phantom-dep:@elysiajs/server-timing | AI (phantom-deps): Elysia plugin referenced in config; stable false positive for this monorepo app package. | ai | |
| phantom-deps | phantom-dep:@contractspec/lib.logger | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive here. | ai |