← Home

@getpara/core-sdk

21
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

nityasnsquaretboschphtoweljordymcnabkwi25

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata no-description AI (npm-metadata): Scoped package with established ecosystem trust; missing description is metadata gap, not malware signal. ai
provenance no-provenance AI (provenance): Known maintainer with strong track record; provenance absence is infrastructure gap, not integrity risk. ai
publish-pattern new-deps-added AI (publish-pattern): xstate is a well-established state machine library; addition is consistent with new state machine files in the diff. ai
source-diff large-new-source-files AI (source-diff): 177 new files correspond to xstate state machine types and implementation; legitimate feature addition. ai
source-diff source-size-tripled AI (source-diff): Size increase driven by xstate integration and large .d.ts type files; not injected payload. ai
dependencies unvetted-dep:elliptic AI (dependencies): elliptic is a standard crypto library; expected dependency for a wallet/crypto SDK. ai
bogus-package bogus-package AI (bogus-package): Established scoped SDK package; missing metadata is a style choice, not a spam indicator. ai

Versions (showing 21 of 21)

Version Deps Published
3.1.0 23 / 2
3.0.0 22 / 2
2.27.0 12 / 2
2.25.0 12 / 2
2.24.0 12 / 2
2.23.0 12 / 2
2.22.0 12 / 2
2.21.0 12 / 2
2.20.0 12 / 2
2.16.0 10 / 2
2.15.0 10 / 2
2.12.0 9 / 2
2.11.0 9 / 2
2.10.0 9 / 2
2.8.0 9 / 2
2.7.0 9 / 2
2.6.0 9 / 2
2.5.0 9 / 2
2.2.0 9 / 2
2.1.0 9 / 2
2.0.0 9 / 2