@peac/core
DEPRECATED - Use @peac/kernel, @peac/schema, @peac/crypto, @peac/protocol instead
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @peac/core belongs to peacprotocol org; Levenshtein match to 'cors' is coincidental. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a declared dependency; phantom-dep heuristic fires due to indirect/config-only usage in this deprecated wrapper package. | ai | |
| phantom-deps | phantom-dep:lru-cache | AI (phantom-deps): lru-cache is a declared dependency; same heuristic false-positive as zod for this deprecated wrapper. | ai |
v0.9.31
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: peacprotocol.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.18
2 findingsPackage name '@peac/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.