@goldstack/template-lambda-http-cli
Utilities for templates that allow a Lambda to function as a web server.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@goldstack/utils-log | AI (phantom-deps): Same-org phantom dep, config reference only. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-config | AI (dependencies): Same-org monorepo dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package | AI (dependencies): Same-org monorepo dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-template | AI (dependencies): Same-org monorepo dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-aws-lambda | AI (dependencies): Same-org monorepo dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package-config | AI (dependencies): Same-org monorepo dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/infra | AI (dependencies): Same-org monorepo dependency, stable across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/infra-aws | AI (dependencies): Same-org monorepo dependency, stable across versions. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-aws-lambda | AI (phantom-deps): Same-org monorepo package; phantom-dep is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): source-map-support is a common runtime dep referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-config | AI (phantom-deps): Same-org monorepo package; phantom-dep is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-template | AI (phantom-deps): Same-org monorepo package; phantom-dep is a stable false positive here. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 0.5.110 | 14 / 11 | |
| 0.5.109 | 14 / 11 | |
| 0.5.108 | 14 / 11 | |
| 0.5.107 | 14 / 11 | |
| 0.5.106 | 14 / 11 | |
| 0.5.72 | 14 / 13 | |
| 0.5.57 | 14 / 13 | |
| 0.5.55 | 14 / 13 | |
| 0.5.51 | 14 / 13 | |
| 0.5.50 | 14 / 13 | |
| 0.5.48 | 14 / 13 | |
| 0.5.46 | 14 / 13 | |
| 0.5.45 | 14 / 13 | |
| 0.5.43 | 14 / 13 | |
| 0.5.42 | 14 / 13 | |
| 0.5.39 | 14 / 13 | |
| 0.5.38 | 14 / 13 | |
| 0.5.37 | 14 / 13 | |
| 0.5.35 | 14 / 13 | |
| 0.5.33 | 14 / 13 | |
| 0.5.32 | 14 / 13 | |
| 0.5.31 | 14 / 13 |
v0.5.110
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.109
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.108
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.107
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.57
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.55
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.50
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.48
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.46
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.45
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.