@crossdelta/platform-sdk
Platform toolkit for event-driven microservices — keeping code and infrastructure in lockstep.
1
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
marcelle
Keywords
cliscaffoldingmicroservicesturborepomonorepopulumiinfrastructure-as-codehononestjsbundevtools
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:ai | AI (phantom-deps): Externalized in esbuild config, used indirectly. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Well-known templating lib used for scaffolding templates. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Bundled CLI code using child_process for normal scaffolding tasks. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Used in config/watch tooling, not direct import. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Bundled dotenv vendor code, not custom payload logic. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander is bundled into cli.js via esbuild; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:package-up | AI (phantom-deps): package-up is bundled into cli.js; phantom-dep false positive. | ai | |
| install-scripts | install-script:postinstall | FP sweep: benign dev-tooling install script (git-hooks/husky/patch-package/build/codegen etc.), verified from tarball; not malware. Flip disposition to accept. | sean | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is bundled externally via esbuild config; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:zx | AI (phantom-deps): zx is listed as an esbuild external and used in CLI templates/config; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:vite | AI (phantom-deps): vite is an esbuild external; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:rimraf | AI (phantom-deps): rimraf is a declared dep used in build scripts; phantom-dep false positive. | ai | |
| phantom-deps | phantom-dep:@faker-js/faker | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:@inquirer/prompts | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:@listr2/prompt-adapter-enquirer | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Fires in minified CLI bundle; code samples show template literals and CLI output, not malicious hex decoding. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Fires in minified CLI bundle on normal config/env handling patterns, not credential exfiltration. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output, not directly imported in analyzed source. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:globby | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:enquirer | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:ts-morph | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:cli-table3 | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai | |
| phantom-deps | phantom-dep:terminal-link | AI (phantom-deps): Bundled CLI tool; deps consumed in bundled output. | ai |
Versions (showing 1 of 101)
| Version | Deps | Published |
|---|---|---|
| 0.1.3 | 21 / 15 |