@fugood/bricks-ctor
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Established publisher; missing description is low-risk metadata issue. | ai | |
| provenance | no-provenance | AI (provenance): Provenance attestation is optional; publisher has strong track record. | ai | |
| dependencies | unvetted-dep:@huggingface/gguf | AI (dependencies): @huggingface/gguf is a legitimate HuggingFace library; stable dependency for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped private/internal package; missing metadata is consistent with org-internal tooling, not spam. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Passing process.env to child Electron process is standard dev-tool pattern. | ai | |
| phantom-deps | phantom-dep:@fugood/bricks-cli | AI (phantom-deps): Same-org CLI companion; likely used via bin or indirect require. | ai | |
| phantom-deps | phantom-dep:@types/bun | AI (phantom-deps): @types packages are ambient type declarations, not runtime imports. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): @types packages are ambient type declarations, not runtime imports. | ai | |
| phantom-deps | phantom-dep:@types/escodegen | AI (phantom-deps): @types packages are ambient type declarations, not runtime imports. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 2.25.0 | 1 / 0 | |
| 2.24.13 | 14 / 0 | |
| 2.24.12 | 14 / 0 | |
| 2.24.11 | 14 / 0 | |
| 2.24.10 | 14 / 0 | |
| 2.24.9 | 14 / 0 | |
| 2.24.8 | 14 / 0 | |
| 2.24.7 | 14 / 0 | |
| 2.24.6 | 14 / 0 | |
| 2.24.5 | 14 / 0 | |
| 2.24.4 | 14 / 0 | |
| 2.24.3 | 14 / 0 | |
| 2.24.2 | 14 / 0 | |
| 2.24.1 | 14 / 0 | |
| 2.24.0 | 13 / 0 |
v2.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.