@pisell/core
39
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
wang_hanzsj1037797769zhiwei.wangxiangfeng.xueah-scjinglin.tanjinhui02
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:dva | AI (phantom-deps): dva is a declared runtime dep used via config/framework wiring, not direct import; stable false positive. | ai | |
| dependencies | unvetted-dep:dva | AI (dependencies): dva is a well-known Alibaba/umijs state management framework; stable dependency for this React utility package. | ai | |
| dependencies | unvetted-dep:dva-core | AI (dependencies): dva-core is the core runtime of dva; same rationale as dva, stable for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped internal package with 82 versions and 522-day history; sparse metadata is a stable pattern, not a malware indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all versions of this scoped package; not indicative of malicious intent. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @pisell/core; 'core' is a generic name, not an impersonation of 'cors'. 82 versions over 516 days confirms legitimate project. | ai |
Versions (showing 39 of 39)
| Version | Deps | Published |
|---|---|---|
| 1.1.5 | 10 / 7 | |
| 1.1.4 | 10 / 7 | |
| 1.1.3 | 10 / 7 | |
| 1.1.2 | 10 / 7 | |
| 1.1.1 | 10 / 7 | |
| 1.0.74 | 12 / 7 | |
| 1.0.72 | 12 / 7 | |
| 1.0.69 | 11 / 7 | |
| 1.0.68 | 11 / 7 | |
| 1.0.67 | 11 / 7 | |
| 1.0.62 | 11 / 7 | |
| 1.0.61 | 11 / 7 | |
| 1.0.58 | 11 / 7 | |
| 1.0.57 | 11 / 7 | |
| 1.0.56 | 11 / 7 | |
| 1.0.53 | 11 / 7 | |
| 1.0.51 | 11 / 7 | |
| 1.0.48 | 11 / 7 | |
| 1.0.45 | 11 / 7 | |
| 1.0.43 | 11 / 7 | |
| 1.0.42 | 11 / 7 | |
| 1.0.41 | 11 / 7 | |
| 1.0.39 | 11 / 7 | |
| 1.0.38 | 11 / 7 | |
| 1.0.37 | 11 / 7 | |
| 1.0.35 | 11 / 7 | |
| 1.0.34 | 10 / 7 | |
| 1.0.33 | 10 / 7 | |
| 1.0.32 | 10 / 7 | |
| 1.0.31 | 10 / 7 | |
| 1.0.29 | 10 / 7 | |
| 1.0.28 | 10 / 7 | |
| 1.0.24 | 10 / 7 | |
| 1.0.22 | 10 / 7 | |
| 1.0.20 | 10 / 7 | |
| 1.0.17 | 10 / 7 | |
| 1.0.16 | 10 / 7 | |
| 1.0.5 | 9 / 7 | |
| 1.0.0 | 0 / 5 |
v1.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.