← Home

@nocobase/server

<video width="100%" controls> <source src="https://github.com/user-attachments/assets/4d11a87b-00e2-48f3-9bf7-389d21072d13" type="video/mp4"> </video>

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

chenosjiannlu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/decompress AI (phantom-deps): Type declaration package; framework-scoped, no runtime risk. ai
phantom-deps phantom-dep:find-package-json AI (phantom-deps): Standard package discovery utility; indirect usage expected in this framework. ai
phantom-deps phantom-dep:@formily/json-schema AI (phantom-deps): Well-known Alibaba form library; indirect usage expected in NocoBase framework. ai
phantom-deps phantom-dep:@types/ini AI (phantom-deps): Type declaration package; framework-scoped, no runtime risk. ai
phantom-deps phantom-dep:@types/multer AI (phantom-deps): Type declaration package; framework-scoped, no runtime risk. ai
phantom-deps phantom-dep:@types/koa-send AI (phantom-deps): Type declaration package; framework-scoped, no runtime risk. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Standard utility declared in package.json for a large Koa framework; indirect import pattern is expected in monorepo packages. ai
phantom-deps phantom-dep:multer AI (phantom-deps): Standard file-upload middleware declared in package.json; indirect usage pattern expected in this framework. ai
phantom-deps phantom-dep:p-queue AI (phantom-deps): Standard async queue utility; indirect usage expected in large framework package. ai
phantom-deps phantom-dep:koa-send AI (phantom-deps): Standard Koa static file serving utility; indirect usage expected. ai
phantom-deps phantom-dep:cronstrue AI (phantom-deps): Cron description utility consistent with the cron dependency; indirect usage expected. ai
phantom-deps phantom-dep:koa-static AI (phantom-deps): Standard Koa static middleware; indirect usage expected in this framework. ai
phantom-deps phantom-dep:@koa/multer AI (phantom-deps): Standard Koa file upload middleware; indirect usage expected. ai
phantom-deps phantom-dep:@koa/router AI (phantom-deps): Standard Koa router; indirect usage expected in this framework. ai
phantom-deps phantom-dep:async-mutex AI (phantom-deps): Standard async locking utility; indirect usage expected. ai
phantom-deps phantom-dep:@nocobase/sdk AI (phantom-deps): Same-org sibling package; indirect usage expected in NocoBase monorepo. ai
phantom-deps phantom-dep:@nocobase/evaluators AI (phantom-deps): Same-org sibling package; indirect usage expected in NocoBase monorepo. ai
semgrep semgrep:hex-decode AI (semgrep): Hex encoding/decoding in an AES-256-CBC decryptor is standard cryptographic practice, not payload obfuscation. Stable false positive for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in gateway/index.js is a plugin/module loading pattern for a server framework, not arbitrary code execution from untrusted input. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() in a Proxy handler is idiomatic JavaScript for transparent proxy forwarding, not API evasion. Standard pattern in this framework. ai
bogus-package bogus-package AI (bogus-package): NocoBase is a well-known open-source no-code platform. Missing repo/homepage in npm package.json and README formatting are packaging oversights, not spam/malware indicators. ai
typosquat typosquat.levenshtein:semver AI (typosquat): @nocobase/server is a legitimate, long-standing server framework package with 1013 versions. The levenshtein match to 'semver' is a false positive — these are entirely different packages. ai

Versions (showing 51 of 125)

View all versions
Version Deps Published
2.0.61 50 / 3
2.0.60 50 / 3
2.0.59 50 / 3
2.0.58 50 / 3
2.0.57 50 / 3
2.0.56 50 / 3
2.0.55 50 / 3
2.0.54 50 / 3
2.0.53 50 / 3
2.0.52 50 / 3
2.0.51 50 / 3
2.0.50 50 / 3
2.0.49 50 / 3
2.0.48 50 / 3
2.0.47 50 / 3
2.0.46 50 / 3
2.0.45 50 / 3
2.0.44 50 / 3
2.0.43 50 / 3
2.0.42 50 / 3
2.0.41 50 / 3
2.0.40 50 / 3
2.0.39 50 / 3
2.0.38 50 / 3
2.0.37 50 / 3
2.0.36 50 / 3
2.0.35 50 / 3
2.0.34 50 / 3
2.0.33 50 / 3
2.0.32 50 / 3
2.0.31 50 / 3
2.0.30 50 / 3
2.0.29 50 / 3
2.0.28 50 / 3
2.0.27 50 / 3
2.0.26 50 / 3
2.0.25 50 / 3
2.0.24 50 / 3
2.0.23 50 / 3
2.0.22 50 / 3
2.0.21 50 / 3
2.0.20 50 / 3
2.0.19 50 / 3
2.0.18 50 / 3
2.0.17 50 / 3
2.0.16 50 / 3
2.0.15 50 / 3
2.0.14 50 / 3
2.0.13 50 / 3
2.0.12 50 / 3
2.0.11 50 / 3

v2.0.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.60

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.50

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.49

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.48

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.47

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.43

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'semver' typosquat

Package name '@nocobase/server' is 1 edit(s) away from popular package 'semver'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.