← Home

@itentialopensource/adapter-rackn_digital_rebar

This adapter integrates with system described as: Digital Rebar Provision Server.

3
Versions
Apache-2.0
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

jared.obrienjohnpolanskyzack.strulovitchitential-ciandyknaebelishitaprakash

Keywords

ItentialItential PlatformAutomationIntegrationAdapterrackn_digital_rebarPre-Release

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:mocha-param AI (dependencies): mocha-param is a test utility dependency; not a runtime risk for this adapter package. ai
semgrep semgrep:dynamic-require AI (semgrep): All 24 instances resolve local __dirname-relative JSON/module paths; no user-controlled input. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used for adapter tooling utilities; standard pattern in Itential adapter base. ai
install-scripts install-script:preinstall AI (install-scripts): Standard Itential adapter setup script pattern; consistent across all 32 versions of this package family. ai
phantom-deps phantom-dep:prompts AI (phantom-deps): prompts used in interactive CLI utilities; referenced in config/util files per analyzer note. ai
phantom-deps phantom-dep:mocha-param AI (phantom-deps): mocha-param used in test scripts; referenced in config files as noted by analyzer. ai
phantom-deps phantom-dep:ping AI (phantom-deps): ping is used in connectivity/healthcheck scripts referenced in package.json scripts block. ai

Versions (showing 3 of 3)

Version Deps Published
1.0.2 15 / 6
1.0.1 15 / 6
1.0.0 15 / 6

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

2 findings
HIGH Package has 'preinstall' script install-scripts

Script: node utils/setup.js

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.