@goldstack/template-ssr-server
Building blocks for implementing server-side rendered pages.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Goldstack monorepo packages consistently lack provenance; stable false positive for this org. | ai | |
| phantom-deps | phantom-dep:@goldstack/infra-aws | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-package | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-template | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-terraform | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-sh | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-package-config-embedded | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/aws-lambda | AI (phantom-deps): Framework-scoped type package; phantom-dep is a stable false positive. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): Referenced in config files by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-aws-lambda | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 0.3.111 | 16 / 12 | |
| 0.3.110 | 16 / 12 | |
| 0.3.105 | 16 / 12 | |
| 0.3.104 | 16 / 12 | |
| 0.3.103 | 16 / 12 | |
| 0.3.101 | 16 / 12 | |
| 0.3.100 | 16 / 12 | |
| 0.3.99 | 16 / 12 | |
| 0.3.92 | 16 / 12 | |
| 0.3.91 | 16 / 13 | |
| 0.3.89 | 16 / 14 | |
| 0.3.83 | 16 / 14 | |
| 0.3.73 | 16 / 14 | |
| 0.3.71 | 16 / 14 |
v0.3.111
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.110
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.105
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.104
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.103
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.101
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.100
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.99
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.92
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.91
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.89
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.83
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.73
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.71
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.