← Home

@flowlib/nestjs

A NestJS module for executing Flowlib workflows with batch processing capabilities

9
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

robase-gh

Keywords

aianthropicbatch-processingflowlibnestjsopenaiworkflow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is consistent with SLSA-attested CI/CD pipeline; stable pattern for this package. ai
phantom-deps phantom-dep:@flowlib/action-kit AI (phantom-deps): Same-org dep; same rationale as @flowlib/db. ai
phantom-deps phantom-dep:@flowlib/db AI (phantom-deps): Same-org sibling dep in a monorepo; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): rxjs is a standard NestJS peer dependency; declared but not directly imported is expected for NestJS modules. ai
phantom-deps phantom-dep:@nestjs/core AI (phantom-deps): NestJS core is a peer dep; not directly imported in module packages is standard pattern. ai
phantom-deps phantom-dep:reflect-metadata AI (phantom-deps): reflect-metadata is a known implicit runtime dep for NestJS/TypeScript decorators; not directly imported is expected. ai

Versions (showing 9 of 9)

Version Deps Published
0.0.10 8 / 12
0.0.8 8 / 12
0.0.7 8 / 12
0.0.6 8 / 12
0.0.5 7 / 12
0.0.4 5 / 12
0.0.3 5 / 12
0.0.2 5 / 12
0.0.1 5 / 12

v0.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.