@instantdb/platform
Instant's platform package for managing Instant apps.
2
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
stopachkanezajdwwdrew-h
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Standard JWT/token decoding in clerk.ts; not obfuscation or payload hiding. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently publishes via GitHub Actions with SLSA provenance attestation; this is the expected publishing pattern for @instantdb/platform. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by CI/CD-published release with SLSA provenance is not indicative of takeover for this established InstantDB sub-package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation from the official instantdb/instant repo. This is a legitimate CI/CD migration, stable for this package going forward. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removal is consistent with migration to GitHub Actions CI/CD publishing. SLSA attestation confirms artifact integrity from the official repo. | ai | |
| dependencies | unvetted-dep:@instantdb/core | AI (dependencies): @instantdb/core is a sibling package from the same InstantDB monorepo, published at matching versions. The unvetted status is a review-ordering artifact, not a security concern. | ai |