@fugood/buttress-server
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:public/lib/index.mjs | AI (source-diff): Bundled build output (tsdown/rolldown), not true obfuscation; matches project's build script. | ai | |
| phantom-deps | phantom-dep:onnxruntime-node | AI (phantom-deps): Native binary dep used via bundled build, consistent with ML server functionality. | ai | |
| phantom-deps | phantom-dep:sharp | AI (phantom-deps): Known implicit runtime/binary dependency. | ai | |
| phantom-deps | phantom-dep:jose | AI (phantom-deps): Bundled ESM output inlines imports; phantom-dep is a stable false positive for this package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Server framework reading env config in bundled output; expected pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Missing description is a metadata gap, not a security concern for this established package. | ai | |
| phantom-deps | phantom-dep:node-machine-id | AI (phantom-deps): Declared in package.json; bundled output inlines deps. | ai | |
| phantom-deps | phantom-dep:@huggingface/gguf | AI (phantom-deps): Declared in package.json; bundled output inlines deps. | ai | |
| phantom-deps | phantom-dep:ms | AI (phantom-deps): Declared in package.json; bundled output inlines deps so direct import not visible to static analysis. | ai | |
| phantom-deps | phantom-dep:@fugood/whisper.node | AI (phantom-deps): Same-org dep declared in package.json; bundled output inlines deps. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Fires in minified bundle; snippet shows normal ESM import pattern, not an obfuscated payload. | ai | |
| phantom-deps | phantom-dep:@fugood/llama.node | AI (phantom-deps): Same-org dep declared in package.json; bundled output inlines deps. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Declared in package.json; bundled output inlines deps. | ai | |
| phantom-deps | phantom-dep:bytes | AI (phantom-deps): Declared in package.json; bundled output inlines deps. | ai | |
| phantom-deps | phantom-dep:@iarna/toml | AI (phantom-deps): Declared in package.json; bundled output inlines deps. | ai | |
| phantom-deps | phantom-dep:@elysiajs/cors | AI (phantom-deps): Declared in package.json; bundled output inlines deps. | ai | |
| phantom-deps | phantom-dep:@elysiajs/node | AI (phantom-deps): Declared in package.json; bundled output inlines deps. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 2.25.0 | 14 / 2 | |
| 2.24.13 | 12 / 2 | |
| 2.24.12 | 12 / 2 | |
| 2.24.11 | 12 / 2 | |
| 2.24.10 | 12 / 2 | |
| 2.24.9 | 12 / 2 | |
| 2.24.8 | 12 / 2 | |
| 2.24.7 | 12 / 2 | |
| 2.24.6 | 12 / 2 | |
| 2.24.5 | 12 / 2 | |
| 2.24.4 | 12 / 2 | |
| 2.24.3 | 12 / 2 | |
| 2.24.2 | 11 / 2 | |
| 2.24.1 | 11 / 2 | |
| 2.24.0 | 11 / 2 | |
| 2.23.9 | 11 / 2 | |
| 2.23.8 | 11 / 2 | |
| 2.23.7 | 11 / 2 | |
| 2.23.6 | 11 / 2 | |
| 2.23.5 | 11 / 2 | |
| 2.23.4 | 11 / 2 | |
| 2.23.3 | 11 / 2 | |
| 2.23.0 | 11 / 2 |
v2.25.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.