← Home

@flink-app/flink

Typescript only framework for creating REST-like APIs on top of Express and mongodb

4
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

joelsojenkins-frostjohanfrost

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@types/ms AI (dependencies): @types/ms is a TypeScript type definition package; no runtime risk for this framework. ai
semgrep semgrep:child-process-import AI (semgrep): child_process.fork used to run the built app; standard for a Node.js framework CLI runner. ai
phantom-deps phantom-dep:croner AI (phantom-deps): Framework peer/optional dependency; stable false positive for this package. ai
phantom-deps phantom-dep:mkdirp AI (phantom-deps): Framework peer/optional dependency; stable false positive for this package. ai
phantom-deps phantom-dep:passport AI (phantom-deps): Framework peer/optional dependency; stable false positive for this package. ai
phantom-deps phantom-dep:passport-jwt AI (phantom-deps): Framework peer/optional dependency; stable false positive for this package. ai
phantom-deps phantom-dep:folder-hash AI (phantom-deps): Framework peer/optional dependency; stable false positive for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): CLI dispatcher pattern loading subcommands by name; stable and expected for this framework's CLI. ai
phantom-deps phantom-dep:@types/cors AI (phantom-deps): Framework-scoped type package; stable false positive. ai
phantom-deps phantom-dep:@types/uuid AI (phantom-deps): Framework-scoped type package; stable false positive. ai
phantom-deps phantom-dep:@types/express AI (phantom-deps): Framework-scoped type package; stable false positive. ai
phantom-deps phantom-dep:@types/fs-extra AI (phantom-deps): Framework-scoped type package; stable false positive. ai
phantom-deps phantom-dep:reflect-metadata AI (phantom-deps): Known implicit runtime dependency for decorator-based frameworks; stable false positive. ai
phantom-deps phantom-dep:@types/body-parser AI (phantom-deps): Framework-scoped type package; stable false positive. ai
phantom-deps phantom-dep:@types/ms AI (phantom-deps): Framework-scoped type package; stable false positive. ai

Versions (showing 4 of 4)

Version Deps Published
1.0.0 28 / 10
0.13.5 28 / 8
0.13.1 28 / 8
0.13.0 28 / 8

v0.13.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.