@platformatic/service
Platformatic Service is an HTTP service built on top of [Fastify](https://fastify.dev/) that provides a foundation for building APIs with auto-generated OpenAPI documentation and GraphQL support.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Established package; empty description is metadata quirk, not malware indicator. | ai | |
| dependencies | unvetted-dep:env-schema | AI (dependencies): Well-known Fastify ecosystem package for env validation; stable false positive. | ai | |
| dependencies | unvetted-dep:my-ua-parser | AI (dependencies): UA parsing utility; consistent dependency across Platformatic versions. | ai | |
| dependencies | unvetted-dep:semgrator | AI (dependencies): Platformatic-ecosystem migration tool; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:close-with-grace | AI (dependencies): Well-known graceful shutdown utility from Fastify ecosystem. | ai | |
| dependencies | unvetted-dep:@fastify/under-pressure | AI (dependencies): Official Fastify plugin for load shedding; stable false positive. | ai | |
| dependencies | unvetted-dep:@fastify/accepts | AI (dependencies): Official Fastify plugin; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:env-schema | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:cli-progress | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@fastify/error | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:fast-json-patch | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@fastify/accepts | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): CLI utility declared in deps; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:code-block-writer | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@fastify/deepmerge | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@platformatic/metrics | AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:console-table-printer | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): Type package declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): Type package declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:close-with-grace | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:rfdc | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:undici | AI (phantom-deps): Known implicit/runtime dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:help-me | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:minimist | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:colorette | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 3.55.0 | 39 / 16 | |
| 3.54.0 | 39 / 16 | |
| 3.53.0 | 39 / 16 | |
| 3.52.4 | 39 / 16 | |
| 3.52.1 | 39 / 16 | |
| 3.52.0 | 39 / 16 | |
| 3.51.0 | 39 / 16 | |
| 3.49.1 | 39 / 16 | |
| 3.48.0 | 39 / 16 | |
| 3.47.0 | 39 / 16 | |
| 3.46.0 | 39 / 16 | |
| 3.41.0 | 39 / 16 | |
| 3.40.0 | 39 / 16 | |
| 3.39.0 | 39 / 16 | |
| 3.36.0 | 39 / 16 | |
| 3.34.1 | 39 / 16 | |
| 3.32.0 | 39 / 16 | |
| 3.31.0 | 39 / 16 | |
| 3.28.2 | 39 / 16 | |
| 3.28.1 | 39 / 16 | |
| 3.19.0 | 39 / 16 | |
| 3.15.0 | 39 / 16 |
v3.55.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.54.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.53.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.52.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.52.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.52.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.51.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.49.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.41.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.40.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.39.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.36.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.34.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.31.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.28.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.28.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.19.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.