← Home

@kyro-cms/core

Astro-native headless CMS with multi-database adapters, multi-protocol APIs, and multi-vendor support

14
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

danieldozie

Keywords

cmsastroheadlesstrpcgraphqlrestwebsocketdrizzlemongodbmultitenantecommerceadmin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:ssh2 AI (phantom-deps): SFTP/SSH feature dependency; loaded conditionally by protocol adapter. ai
phantom-deps phantom-dep:cpu-features AI (phantom-deps): Transitive/optional native dep for sharp; stable false positive. ai
phantom-deps phantom-dep:jsondiffpatch AI (phantom-deps): Diff utility loaded conditionally; stable false positive for this package. ai
phantom-deps phantom-dep:ssh2-sftp-client AI (phantom-deps): SFTP adapter loaded conditionally; stable false positive. ai
phantom-deps phantom-dep:@aws-sdk/s3-request-presigner AI (phantom-deps): AWS S3 adapter loaded by convention; stable false positive. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped CMS package @kyro-cms/core; name reflects the org/product, not an attempt to impersonate cors. ai
phantom-deps phantom-dep:mongodb AI (phantom-deps): Optional adapter exposed via ./mongodb sub-path export; not imported in core but legitimately declared. ai
phantom-deps phantom-dep:@trpc/client AI (phantom-deps): Optional tRPC adapter via ./trpc sub-path export; conditional usage pattern. ai
phantom-deps phantom-dep:@trpc/server AI (phantom-deps): Optional tRPC adapter via ./trpc sub-path export; conditional usage pattern. ai
phantom-deps phantom-dep:@trpc/react-query AI (phantom-deps): Optional tRPC adapter via ./trpc sub-path export; conditional usage pattern. ai
phantom-deps phantom-dep:esbuild AI (phantom-deps): Known build/bundling implicit dependency; legitimate for a CMS build tool. ai
phantom-deps phantom-dep:ora AI (phantom-deps): CLI spinner used in CLI scripts; may not be directly imported in analyzed entry points. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): CLI output utility; referenced in config/CLI scripts, legitimate usage pattern. ai

Versions (showing 14 of 14)

Version Deps Published
0.2.10 28 / 18
0.2.9 28 / 18
0.2.4 29 / 17
0.2.2 29 / 17
0.2.1 29 / 17
0.2.0 29 / 17
0.1.9 29 / 17
0.1.8 29 / 17
0.1.7 28 / 17
0.1.6 20 / 16
0.1.5 20 / 16
0.1.4 20 / 16
0.1.3 20 / 16
0.1.2 20 / 16

v0.2.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.