@hyperspaceng/neural-ai
Unified LLM API with automatic model discovery and provider configuration
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@sinclair/typebox | AI (phantom-deps): Schema definition library; stable for this package. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): Schema validation extension; stable for this package. | ai | |
| phantom-deps | phantom-dep:proxy-agent | AI (phantom-deps): Network utility for provider clients; stable for this package. | ai | |
| phantom-deps | phantom-dep:partial-json | AI (phantom-deps): Streaming JSON parser for LLM responses; stable for this package. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): Conditionally imported via ./openai-* subpath exports; stable pattern for multi-provider library. | ai | |
| phantom-deps | phantom-dep:@anthropic-ai/sdk | AI (phantom-deps): Conditionally imported via ./anthropic subpath export; stable pattern for multi-provider library. | ai | |
| phantom-deps | phantom-dep:@google/genai | AI (phantom-deps): Conditionally imported via ./google* subpath exports; stable pattern for multi-provider library. | ai | |
| phantom-deps | phantom-dep:@mistralai/mistralai | AI (phantom-deps): Conditionally imported via ./mistral subpath export; stable pattern for multi-provider library. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-bedrock-runtime | AI (phantom-deps): Conditionally imported via ./bedrock-provider subpath export; stable pattern for multi-provider library. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Schema validation dependency used in config files; stable for this package. | ai | |
| phantom-deps | phantom-dep:undici | AI (phantom-deps): undici is a runtime dependency for HTTP; implicit usage is expected. | ai | |
| phantom-deps | phantom-dep:zod-to-json-schema | AI (phantom-deps): zod-to-json-schema is declared and used in schema generation; heuristic false positive. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): chalk is declared and used in config/CLI output; heuristic false positive. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 0.70.7 | 11 / 3 | |
| 0.70.6 | 11 / 3 | |
| 0.70.3 | 11 / 3 | |
| 0.70.1 | 11 / 3 | |
| 0.69.1 | 11 / 3 | |
| 0.68.2 | 13 / 3 | |
| 0.68.1 | 13 / 3 | |
| 0.67.69 | 13 / 3 | |
| 0.67.7 | 13 / 3 | |
| 0.67.4 | 13 / 3 | |
| 0.67.3 | 13 / 3 | |
| 0.67.2 | 13 / 3 | |
| 0.66.2 | 13 / 3 | |
| 0.65.3 | 13 / 3 | |
| 0.65.1 | 13 / 3 | |
| 0.64.1 | 13 / 3 | |
| 0.63.2 | 13 / 3 | |
| 0.63.0 | 13 / 3 | |
| 0.62.1 | 13 / 3 | |
| 0.61.6 | 13 / 3 | |
| 0.61.5 | 13 / 3 | |
| 0.61.4 | 13 / 3 | |
| 0.61.3 | 13 / 3 | |
| 0.61.2 | 13 / 3 | |
| 0.60.0 | 13 / 3 |
v0.70.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.69.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.69
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.66.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.64.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.63.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.63.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.62.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.61.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.61.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.61.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.61.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.61.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.60.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.