@inkandswitch/patchwork-bootloader
9
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
pvhcheeexpedememorythought
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Missing metadata fields, not spam; established publisher/project. | ai | |
| dependencies | unvetted-dep:service-worker-types | AI (dependencies): Type-only package alias, no runtime risk. | ai | |
| dependencies | unvetted-dep:@keyhive/keyhive | AI (dependencies): First-party ecosystem dep for this project's CRDT stack. | ai | |
| dependencies | unvetted-dep:@automerge/automerge-repo-keyhive | AI (dependencies): First-party automerge ecosystem dep, matches peerDependency. | ai | |
| phantom-deps | phantom-dep:solid-js | AI (phantom-deps): Used via framework convention/build tooling, not direct import scan. | ai | |
| phantom-deps | phantom-dep:@codemirror/view | AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. | ai | |
| phantom-deps | phantom-dep:@codemirror/state | AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. | ai | |
| phantom-deps | phantom-dep:@codemirror/commands | AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. | ai | |
| phantom-deps | phantom-dep:@codemirror/language | AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. | ai | |
| semgrep | semgrep:toplevel-fetch | AI (semgrep): Fetches local WASM assets at module load — core bootloader functionality, not telemetry or exfiltration. | ai | |
| phantom-deps | phantom-dep:@automerge/automerge | AI (phantom-deps): Listed as both dep and peer dep; phantom-dep heuristic fires incorrectly here. | ai | |
| phantom-deps | phantom-dep:resolve.exports | AI (phantom-deps): Config-referenced build utility; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/debug | AI (phantom-deps): Type-only dev dependency; framework-scoped, not a real phantom dep risk. | ai | |
| phantom-deps | phantom-dep:service-worker-types | AI (phantom-deps): Type-only package aliased via npm: protocol; not a real phantom dep risk. | ai | |
| phantom-deps | phantom-dep:@automerge/automerge-repo | AI (phantom-deps): Listed as both dep and peer dep; phantom-dep heuristic fires incorrectly here. | ai | |
| phantom-deps | phantom-dep:@automerge/vanillajs | AI (phantom-deps): Listed as both dep and peer dep; phantom-dep heuristic fires incorrectly here. | ai | |
| phantom-deps | phantom-dep:tinyargs | AI (phantom-deps): Build/config reference; not a direct import concern for this package. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 0.4.4 | 23 / 2 | |
| 0.4.0 | 17 / 3 | |
| 0.3.2 | 17 / 3 | |
| 0.2.6 | 17 / 3 | |
| 0.1.1 | 15 / 3 | |
| 0.0.8 | 15 / 3 | |
| 0.0.6 | 15 / 3 | |
| 0.0.5 | 15 / 3 | |
| 0.0.1 | 8 / 4 |
v0.4.4
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.