@hed-hog/contact
O módulo `@hed-hog/contact` gerencia informações relacionadas a contatos, documentos, pessoas e seus tipos, além das relações entre pessoas. Ele oferece funcionalidades completas de CRUD para tipos de contato, tipos de documento, pessoas e suas relações,
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/proposal/proposal.service.js | AI (source-diff): Compiled NestJS service; network calls are API integrations, dynamic code is a Playwright import shim — no malware indicators. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used solely to wrap dynamic import() call, not to execute arbitrary user input. | ai | |
| phantom-deps | phantom-dep:@hed-hog/address | AI (phantom-deps): Same-org sibling dependency; phantom detection is a false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across the entire @hed-hog ecosystem; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@nestjs/core | AI (phantom-deps): @nestjs/core is a peer/framework dep referenced in config; stable false positive for NestJS module packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package pattern; missing metadata is consistent across all @hed-hog/* packages, not a spam indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern for @hed-hog/* monorepo sub-packages; not a malice signal. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 0.0.329 | 12 / 0 | |
| 0.0.316 | 12 / 0 | |
| 0.0.312 | 12 / 0 | |
| 0.0.305 | 12 / 0 | |
| 0.0.302 | 12 / 0 | |
| 0.0.51 | 11 / 0 |
v0.0.329
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.316
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.312
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.305
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.302
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.