@lark-apaas/nestjs-logger
18
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
bytednpmfengtianran_bytedxiaochuanzhang_bytedbyted.lycoirefduanlikang_byteyuki-bytedanceaihao.0331yanmingjiangchengshihao1prgrmr_byte
Keywords
pluginnestjsservertypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): New publisher byted.lycoiref has 163 approved packages and is within the same @lark-apaas org; appears to be a legitimate maintainer transition. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): All new maintainers share byted/lark org naming pattern; consistent with internal team expansion. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are same-org @lark-apaas scoped packages, not third-party supply chain risk. | ai | |
| provenance | no-provenance | AI (provenance): Org-internal package; no provenance is consistent across all versions in this namespace. | ai |