@juspay/neurolink
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Observability dependency used conditionally; consistent with optional telemetry support. | ai | |
| phantom-deps | phantom-dep:@google/generative-ai | AI (phantom-deps): Provider-specific dep used via config; stable false positive for this multi-provider SDK. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a common WebSocket dep used via config/optional paths in a multi-provider AI SDK. | ai | |
| phantom-deps | phantom-dep:mathjs | AI (phantom-deps): mathjs used in config/optional code paths; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:xml2js | AI (phantom-deps): xml2js used in config/optional code paths; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@juspay/hippocampus | AI (dependencies): First-party Juspay dependency; same org as the publisher, consistent with internal library use. | ai | |
| phantom-deps | phantom-dep:ollama-ai-provider | AI (phantom-deps): Multi-provider AI framework; provider SDKs loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-bedrock | AI (phantom-deps): Framework-scoped AWS provider SDK; loaded by convention as noted by analyzer. | ai | |
| phantom-deps | phantom-dep:@huggingface/inference | AI (phantom-deps): Same pattern — provider SDK loaded by convention in multi-provider framework. | ai |
Versions (showing 14 of 215)
| Version | Deps | Published |
|---|---|---|
| 9.40.0 | 60 / 63 | |
| 9.39.0 | 60 / 63 | |
| 9.38.0 | 60 / 63 | |
| 9.37.0 | 59 / 63 | |
| 9.36.1 | 59 / 63 | |
| 9.36.0 | 59 / 63 | |
| 9.35.0 | 59 / 63 | |
| 9.34.0 | 59 / 63 | |
| 9.33.0 | 59 / 62 | |
| 9.32.1 | 59 / 62 | |
| 9.32.0 | 59 / 62 | |
| 9.31.2 | 58 / 62 | |
| 9.31.1 | 58 / 62 | |
| 9.31.0 | 58 / 62 |
v9.39.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.38.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.37.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.36.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.36.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.35.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.34.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.33.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.32.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.31.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.31.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.31.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.