@massu/core
AI Engineering Governance MCP Server - Session memory, knowledge system, feature registry, code intelligence, rule enforcement, tiered tooling (12 free / 72 total), 55+ workflow commands, 11 agents, 20+ patterns
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Used in adapter-verifier.ts to decode a manifest for NaCl signature verification — legitimate crypto use. | ai | |
| phantom-deps | phantom-dep:tar | AI (phantom-deps): Declared dep used indirectly via build scripts; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:vscode-languageserver-protocol | AI (phantom-deps): LSP protocol types likely used via type imports only; stable false positive for this package. | ai | |
| source-diff | net-exec-file:dist/cli.js | AI (source-diff): dist/cli.js is an esbuild-bundled CLI binary declared in package.json bin field; network+exec pattern is from bundled MCP server code, not malware. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @massu/core is a scoped AI governance package, not a typosquat of cors; name collision is coincidental. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Findings are in a security-gate blocklist that detects dangerous patterns, not code that accesses /etc/passwd. | ai |
Versions (showing 66 of 66)
| Version | Deps | Published |
|---|---|---|
| 1.16.2 | 16 / 7 | |
| 1.16.1 | 16 / 7 | |
| 1.16.0 | 16 / 7 | |
| 1.15.7 | 16 / 7 | |
| 1.15.6 | 16 / 7 | |
| 1.15.5 | 16 / 7 | |
| 1.15.3 | 15 / 7 | |
| 1.15.2 | 15 / 7 | |
| 1.15.0 | 15 / 6 | |
| 1.14.0 | 15 / 6 | |
| 1.13.1 | 15 / 6 | |
| 1.13.0 | 15 / 6 | |
| 1.12.2 | 15 / 6 | |
| 1.12.1 | 15 / 6 | |
| 1.12.0 | 15 / 6 | |
| 1.10.8 | 17 / 6 | |
| 1.10.6 | 17 / 6 | |
| 1.10.5 | 17 / 6 | |
| 1.10.4 | 17 / 6 | |
| 1.10.3 | 17 / 6 | |
| 1.10.2 | 17 / 6 | |
| 1.10.1 | 17 / 6 | |
| 1.10.0 | 17 / 6 | |
| 1.9.5 | 17 / 6 | |
| 1.9.3 | 17 / 6 | |
| 1.9.2 | 17 / 6 | |
| 1.9.1 | 17 / 6 | |
| 1.9.0 | 17 / 6 | |
| 1.8.0 | 17 / 6 | |
| 1.7.0 | 17 / 6 | |
| 1.6.3 | 17 / 6 | |
| 1.6.2 | 17 / 6 | |
| 1.6.1 | 17 / 6 | |
| 1.6.0 | 17 / 6 | |
| 1.5.8 | 12 / 6 | |
| 1.5.7 | 12 / 6 | |
| 1.5.6 | 12 / 6 | |
| 1.5.5 | 12 / 6 | |
| 1.5.4 | 12 / 6 | |
| 1.5.3 | 12 / 6 | |
| 1.5.2 | 12 / 6 | |
| 1.5.1 | 12 / 6 | |
| 1.5.0 | 12 / 6 | |
| 1.4.0 | 12 / 6 | |
| 1.3.0 | 6 / 5 | |
| 1.2.1 | 6 / 5 | |
| 1.2.0 | 6 / 5 | |
| 1.1.0 | 6 / 5 | |
| 1.0.0 | 6 / 5 | |
| 0.9.2 | 3 / 5 | |
| 0.9.1 | 3 / 5 | |
| 0.9.0 | 3 / 5 | |
| 0.8.1 | 3 / 5 | |
| 0.8.0 | 3 / 5 | |
| 0.7.0 | 3 / 5 | |
| 0.6.3 | 3 / 5 | |
| 0.6.2 | 3 / 5 | |
| 0.6.1 | 3 / 5 | |
| 0.6.0 | 3 / 5 | |
| 0.5.0 | 3 / 5 | |
| 0.4.2 | 3 / 5 | |
| 0.4.1 | 3 / 5 | |
| 0.4.0 | 3 / 5 | |
| 0.1.2 | 4 / 5 | |
| 0.1.1 | 3 / 5 | |
| 0.1.0 | 3 / 5 |
v1.16.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.