@krynix/core
Core primitives for Krynix: trace events, hash chains, sessions, canonical JSON, and schema validation
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA/Sigstore attestation present; missing gitHead is a minor metadata gap, not a supply-chain risk for this package. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @krynix/core is unrelated to cors; name similarity is coincidental, not impersonation. | ai |
v0.2.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.1
2 findingsPackage name '@krynix/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.