← Home

@learncard/create-http-bridge

Instantly create and deploy a Learn Card Bridge HTTP API via AWS Lambda!

10
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

gerardoparcustard7smurflo2taylorbeestonjonny2lips

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with org-level automation for this established package. ai
dependencies unvetted-dep:serverless-esbuild AI (dependencies): Legitimate serverless build tooling consistent with package purpose; referenced in config files only. ai
dependencies unvetted-dep:ink-syntax-highlight AI (dependencies): CLI UI dependency consistent with interactive terminal tool pattern. ai
dependencies unvetted-dep:serverless-plugin-warmup AI (dependencies): Standard serverless plugin for Lambda warmup; consistent with package purpose. ai
bogus-package bogus-package AI (bogus-package): Legitimate LearnCard org package; README link dump reflects docs-heavy style, not spam. ai
phantom-deps phantom-dep:inquirer AI (phantom-deps): CLI tooling dependency; referenced in config, stable false positive for this package. ai
phantom-deps phantom-dep:serverless-esbuild AI (phantom-deps): Used as serverless plugin via config, not direct import; stable false positive. ai
phantom-deps phantom-dep:serverless-plugin-warmup AI (phantom-deps): Used as serverless plugin via config, not direct import; stable false positive. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): Used via rollup -c CLI in scripts, not direct import; stable false positive. ai

Versions (showing 10 of 10)

Version Deps Published
1.1.238 24 / 12
1.1.237 24 / 12
1.1.236 24 / 12
1.1.235 24 / 12
1.1.234 24 / 12
1.1.233 24 / 12
1.1.232 24 / 12
1.1.230 24 / 12
1.1.229 24 / 12
1.1.228 24 / 12

v1.1.238

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.237

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.236

2 findings
HIGH Publisher changed: custard7 → GitHub Actions (on 2026-05-21) provenance

This version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.235

2 findings
HIGH Publisher changed: custard7 → GitHub Actions (on 2026-05-13) provenance

This version was published by a different npm account than previous versions on 2026-05-13. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.234

2 findings
HIGH Publisher changed: custard7 → GitHub Actions (on 2026-05-12) provenance

This version was published by a different npm account than previous versions on 2026-05-12. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.233

2 findings
HIGH Publisher changed: custard7 → GitHub Actions (on 2026-05-04) provenance

This version was published by a different npm account than previous versions on 2026-05-04. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.232

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.230

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.229

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.228

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.