@ottocode/server
HTTP API server for ottocode
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@solana/web3.js | AI (phantom-deps): Solana integration dependency referenced via config. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Used in config for Solana address encoding, not a runtime import concern. | ai | |
| phantom-deps | phantom-dep:tweetnacl | AI (phantom-deps): Crypto lib referenced via config, consistent with wallet/signing features. | ai | |
| dependencies | unvetted-dep:@ottocode/sdk | AI (dependencies): First-party sibling package from same publisher/monorepo. | ai | |
| dependencies | unvetted-dep:@ottocode/themes | AI (dependencies): First-party sibling package from same publisher/monorepo. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode used for attachment storage, not payload obfuscation. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread is in a git child-process spawn context; inheriting process.env is standard for git tooling. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped package @ottocode/server is an HTTP API server, not a typosquat of semver. The name similarity is coincidental and structural, not deceptive. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): The raw IP references (127.0.0.1) are used for localhost CORS allowlisting, a standard and benign pattern. Not a suspicious outbound connection. | ai |
Versions (showing 51 of 151)
| Version | Deps | Published |
|---|---|---|
| 0.1.224 | 5 / 2 | |
| 0.1.223 | 5 / 2 | |
| 0.1.222 | 5 / 2 | |
| 0.1.221 | 5 / 2 | |
| 0.1.220 | 5 / 2 | |
| 0.1.219 | 5 / 2 | |
| 0.1.218 | 5 / 2 | |
| 0.1.217 | 5 / 2 | |
| 0.1.216 | 5 / 2 | |
| 0.1.215 | 5 / 2 | |
| 0.1.213 | 5 / 2 | |
| 0.1.212 | 5 / 2 | |
| 0.1.211 | 5 / 2 | |
| 0.1.210 | 5 / 2 | |
| 0.1.209 | 5 / 2 | |
| 0.1.208 | 5 / 2 | |
| 0.1.207 | 5 / 2 | |
| 0.1.206 | 5 / 2 | |
| 0.1.205 | 5 / 2 | |
| 0.1.204 | 5 / 2 | |
| 0.1.203 | 5 / 2 | |
| 0.1.202 | 5 / 2 | |
| 0.1.201 | 5 / 2 | |
| 0.1.200 | 5 / 2 | |
| 0.1.199 | 5 / 2 | |
| 0.1.198 | 5 / 2 | |
| 0.1.197 | 5 / 2 | |
| 0.1.196 | 5 / 2 | |
| 0.1.195 | 5 / 2 | |
| 0.1.194 | 5 / 2 | |
| 0.1.193 | 5 / 2 | |
| 0.1.192 | 5 / 2 | |
| 0.1.191 | 5 / 2 | |
| 0.1.190 | 5 / 2 | |
| 0.1.189 | 5 / 2 | |
| 0.1.188 | 5 / 2 | |
| 0.1.187 | 5 / 2 | |
| 0.1.186 | 5 / 2 | |
| 0.1.185 | 5 / 2 | |
| 0.1.184 | 5 / 2 | |
| 0.1.183 | 5 / 2 | |
| 0.1.182 | 5 / 2 | |
| 0.1.181 | 5 / 2 | |
| 0.1.180 | 5 / 2 | |
| 0.1.179 | 5 / 2 | |
| 0.1.178 | 5 / 2 | |
| 0.1.177 | 5 / 2 | |
| 0.1.176 | 5 / 2 | |
| 0.1.175 | 5 / 2 | |
| 0.1.174 | 5 / 2 | |
| 0.1.173 | 5 / 2 |
v0.1.224
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.223
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.222
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.221
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.220
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.219
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.218
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.217
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.216
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.215
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.213
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.212
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.211
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.210
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.209
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.208
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.207
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.206
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.205
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.204
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.203
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.202
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.201
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.200
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.199
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.198
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.197
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.196
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.195
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.192
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.191
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.190
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.189
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.188
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.185
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.181
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.179
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.176
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.175
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.174
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.