@mcpc-tech/code-runner-mcp
15
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
yaonyan
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate automated publishing pattern. | ai | |
| phantom-deps | phantom-dep:json-schema-to-zod | AI (phantom-deps): Referenced in config files but not directly imported; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@mcpc-tech/ripgrep-napi | AI (phantom-deps): Same-org dep referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:deno | AI (phantom-deps): deno is a declared runtime dependency used via config/CLI, not directly imported in JS source; stable FP for this package. | ai |