@premai/pcci-sdk-ts
End-to-end encrypted OpenAI-compatible client with file upload and tools support, using XWing (ML-KEM768 + X25519) hybrid post-quantum encryption.
11
Versions
ISC
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
lorenzodalmazzofederico-prem
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@premAI-io/prem-rs | AI (dependencies): First-party dependency from the same premai-io org; consistent with SDK purpose across versions. | ai | |
| provenance | no-provenance | AI (provenance): Published via GitHub Actions CI; absence of Sigstore attestation is common and not a risk indicator for this package. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): typescript is a declared runtime dep used by the build toolchain; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:@noble/curves | AI (phantom-deps): @noble/curves is a declared runtime dep; phantom-dep heuristic fires due to indirect usage pattern, not a real issue. | ai |