@enbox/dwn-server
> **Research Preview** — Enbox is under active development. APIs may change without notice.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish hygiene gap, not tampering evidence; no malicious behavior found. | ai | |
| dependencies | unvetted-dep:@enbox/dwn-server-admin-ui | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| phantom-deps | phantom-dep:interface-store | AI (phantom-deps): Type-only interface dep for storage backend. | ai | |
| phantom-deps | phantom-dep:interface-blockstore | AI (phantom-deps): Type-only interface dep for storage backend. | ai | |
| phantom-deps | phantom-dep:level | AI (phantom-deps): Used via abstract-level storage backend config, not direct import. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Optional-dependency loader pattern with explicit install-instruction error. | ai | |
| phantom-deps | phantom-dep:ipfs-unixfs-exporter | AI (phantom-deps): IPFS storage dep used indirectly via config. | ai | |
| phantom-deps | phantom-dep:abstract-level | AI (phantom-deps): Storage backend interface dep, referenced via config. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a declared runtime dep used in config/server setup; phantom-dep heuristic fires but it's legitimately used. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 0.1.32 | 15 / 18 | |
| 0.1.31 | 15 / 18 | |
| 0.1.30 | 15 / 18 | |
| 0.1.29 | 15 / 18 | |
| 0.1.28 | 15 / 18 | |
| 0.1.27 | 15 / 18 | |
| 0.1.26 | 15 / 18 | |
| 0.1.25 | 15 / 18 | |
| 0.1.24 | 15 / 18 | |
| 0.1.22 | 15 / 18 | |
| 0.1.21 | 15 / 18 | |
| 0.1.20 | 15 / 18 | |
| 0.1.19 | 15 / 18 | |
| 0.1.18 | 15 / 18 | |
| 0.1.17 | 15 / 18 | |
| 0.1.16 | 15 / 18 | |
| 0.1.15 | 19 / 13 | |
| 0.1.14 | 19 / 13 | |
| 0.1.13 | 19 / 13 | |
| 0.1.12 | 19 / 13 | |
| 0.1.11 | 19 / 13 | |
| 0.1.10 | 19 / 13 | |
| 0.1.9 | 20 / 13 | |
| 0.1.8 | 20 / 13 | |
| 0.1.7 | 20 / 13 | |
| 0.1.6 | 20 / 13 | |
| 0.1.5 | 20 / 13 | |
| 0.1.4 | 20 / 13 | |
| 0.1.3 | 20 / 13 | |
| 0.1.2 | 20 / 13 | |
| 0.1.1 | 20 / 13 | |
| 0.1.0 | 20 / 13 | |
| 0.0.16 | 20 / 13 | |
| 0.0.15 | 20 / 13 | |
| 0.0.14 | 20 / 13 | |
| 0.0.13 | 20 / 13 | |
| 0.0.12 | 20 / 13 | |
| 0.0.11 | 20 / 13 | |
| 0.0.10 | 20 / 13 | |
| 0.0.9 | 20 / 14 | |
| 0.0.8 | 20 / 24 | |
| 0.0.7 | 19 / 24 | |
| 0.0.6 | 19 / 24 | |
| 0.0.5 | 19 / 24 | |
| 0.0.4 | 20 / 24 | |
| 0.0.3 | 15 / 31 | |
| 0.0.2 | 23 / 35 | |
| 0.0.1 | 23 / 35 |
v0.1.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.16
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: itsliran.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.15
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: itsliran.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.14
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: itsliran.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.