@goldstack/template-ssr
Building blocks for implementing server-side rendered pages.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@goldstack/utils-package-config-embedded | AI (dependencies): Same-org monorepo dependency; stable pattern across all goldstack package versions. | ai | |
| dependencies | unvetted-dep:@goldstack/infra-aws | AI (dependencies): Same-org monorepo dependency; stable pattern across all goldstack package versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-esbuild | AI (dependencies): Same-org monorepo dependency; stable pattern across all goldstack package versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package | AI (dependencies): Same-org monorepo dependency; stable pattern across all goldstack package versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-template | AI (dependencies): Same-org monorepo dependency; stable pattern across all goldstack package versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-aws-lambda | AI (dependencies): Same-org monorepo dependency; stable pattern across all goldstack package versions. | ai | |
| dependencies | unvetted-dep:@goldstack/infra | AI (dependencies): Same-org monorepo dependency; stable pattern across all goldstack package versions. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): Referenced in config files by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-esbuild | AI (phantom-deps): Same-org build tooling; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-template | AI (phantom-deps): Same-org utility; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-package-config-embedded | AI (phantom-deps): Same-org utility; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/aws-lambda | AI (phantom-deps): Framework-scoped type package; stable false positive for this package. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 0.3.113 | 13 / 12 | |
| 0.3.104 | 13 / 12 | |
| 0.3.101 | 13 / 12 | |
| 0.3.98 | 13 / 12 | |
| 0.3.97 | 13 / 12 | |
| 0.3.94 | 13 / 12 | |
| 0.3.90 | 13 / 14 | |
| 0.3.85 | 13 / 14 | |
| 0.3.80 | 13 / 14 | |
| 0.3.78 | 13 / 14 | |
| 0.3.75 | 13 / 14 | |
| 0.3.74 | 13 / 14 | |
| 0.3.73 | 13 / 14 | |
| 0.3.66 | 13 / 14 | |
| 0.3.65 | 13 / 14 |
v0.3.113
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.104
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.101
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.98
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.97
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.94
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.90
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.85
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.80
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.75
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.74
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.73
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.66
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.65
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.