← Home

@inkandswitch/patchwork-bootloader

9
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

pvhcheeexpedememorythought

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Missing metadata fields, not spam; established publisher/project. ai
dependencies unvetted-dep:service-worker-types AI (dependencies): Type-only package alias, no runtime risk. ai
dependencies unvetted-dep:@keyhive/keyhive AI (dependencies): First-party ecosystem dep for this project's CRDT stack. ai
dependencies unvetted-dep:@automerge/automerge-repo-keyhive AI (dependencies): First-party automerge ecosystem dep, matches peerDependency. ai
phantom-deps phantom-dep:solid-js AI (phantom-deps): Used via framework convention/build tooling, not direct import scan. ai
phantom-deps phantom-dep:@codemirror/view AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. ai
phantom-deps phantom-dep:@codemirror/state AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. ai
phantom-deps phantom-dep:@codemirror/commands AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. ai
phantom-deps phantom-dep:@codemirror/language AI (phantom-deps): Editor dependency likely referenced via bundled config, not source scan. ai
semgrep semgrep:toplevel-fetch AI (semgrep): Fetches local WASM assets at module load — core bootloader functionality, not telemetry or exfiltration. ai
phantom-deps phantom-dep:@automerge/automerge AI (phantom-deps): Listed as both dep and peer dep; phantom-dep heuristic fires incorrectly here. ai
phantom-deps phantom-dep:resolve.exports AI (phantom-deps): Config-referenced build utility; stable false positive for this package. ai
phantom-deps phantom-dep:@types/debug AI (phantom-deps): Type-only dev dependency; framework-scoped, not a real phantom dep risk. ai
phantom-deps phantom-dep:service-worker-types AI (phantom-deps): Type-only package aliased via npm: protocol; not a real phantom dep risk. ai
phantom-deps phantom-dep:@automerge/automerge-repo AI (phantom-deps): Listed as both dep and peer dep; phantom-dep heuristic fires incorrectly here. ai
phantom-deps phantom-dep:@automerge/vanillajs AI (phantom-deps): Listed as both dep and peer dep; phantom-dep heuristic fires incorrectly here. ai
phantom-deps phantom-dep:tinyargs AI (phantom-deps): Build/config reference; not a direct import concern for this package. ai

Versions (showing 9 of 9)

Version Deps Published
0.4.4 23 / 2
0.4.0 17 / 3
0.3.2 17 / 3
0.2.6 17 / 3
0.1.1 15 / 3
0.0.8 15 / 3
0.0.6 15 / 3
0.0.5 15 / 3
0.0.1 8 / 4

v0.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.