← Home

@platformatic/runtime

Check out the full documentation for Platformatic Runtime on [our website](https://docs.platformatic.dev/docs/reference/runtime/overview).

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

mzugmivan-tymoshenkomarcopiraccinileorossishogun_pandamatteo.collinaqardlucamaraschi

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:prom-client AI (phantom-deps): Platformatic runtime re-exports/proxies metrics; prom-client is a peer used by @platformatic/metrics sibling dep. ai
phantom-deps phantom-dep:@platformatic/metrics AI (phantom-deps): Same-org sibling package; used transitively through the platformatic monorepo runtime wiring. ai
phantom-deps phantom-dep:help-me AI (phantom-deps): CLI help utility; referenced in config, stable false positive. ai
phantom-deps phantom-dep:minimist AI (phantom-deps): CLI arg parsing; referenced in config, stable false positive. ai
phantom-deps phantom-dep:change-case-all AI (phantom-deps): Utility dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:fastest-levenshtein AI (phantom-deps): Utility dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@platformatic/prom-client AI (phantom-deps): Same-org dep; stable false positive. ai
phantom-deps phantom-dep:pino-opentelemetry-transport AI (phantom-deps): Optional transport dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): Peer/optional telemetry dep; stable false positive for this package. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): Declared dep used as optional/peer dependency in config; stable false positive for this package. ai
semgrep semgrep:env-spread AI (semgrep): Intentional management API endpoint exposing runtime env; expected behavior for a runtime orchestration package. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Fetches 127.0.0.1 for Node.js inspector protocol — standard local debugging pattern, not exfiltration. ai

Versions (showing 51 of 87)

View all versions
Version Deps Published
3.62.2 35 / 32
3.62.1 35 / 32
3.62.0 35 / 32
3.61.1 35 / 32
3.61.0 35 / 32
3.60.0 35 / 32
3.59.0 34 / 31
3.58.1 34 / 31
3.58.0 34 / 31
3.57.0 34 / 29
3.56.0 34 / 29
3.55.0 33 / 29
3.54.0 33 / 29
3.53.0 33 / 29
3.52.4 33 / 29
3.52.3 33 / 29
3.52.2 33 / 29
3.52.1 33 / 29
3.52.0 33 / 29
3.51.0 33 / 29
3.50.0 34 / 28
3.49.1 33 / 28
3.49.0 33 / 28
3.48.0 33 / 28
3.47.0 33 / 28
3.46.0 33 / 28
3.45.0 33 / 28
3.44.0 33 / 28
3.43.0 33 / 28
3.42.0 33 / 28
3.41.0 33 / 28
3.40.0 33 / 28
3.39.0 33 / 28
3.38.1 32 / 28
3.38.0 32 / 28
3.37.0 32 / 28
3.36.0 32 / 28
3.35.1 32 / 28
3.35.0 32 / 28
3.34.1 32 / 28
3.33.0 32 / 28
3.32.0 32 / 28
3.31.0 32 / 28
3.30.0 32 / 28
3.29.1 32 / 28
3.29.0 32 / 28
3.28.2 32 / 28
3.28.1 32 / 28
3.28.0 32 / 28
3.27.0 32 / 28
3.26.0 32 / 28

v3.62.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.62.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.61.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.61.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.60.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.59.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.58.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.58.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.