← Home

@proto-kit/indexer

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

rpanicmaht0rz

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:ink AI (phantom-deps): Monorepo CLI tool; ink is a runtime dep resolved via workspace, not a direct import. ai
phantom-deps phantom-dep:react AI (phantom-deps): React is a peer/runtime dep for ink CLI; resolved via workspace root. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): CLI tooling dep; resolved via workspace root in monorepo context. ai
phantom-deps phantom-dep:figlet AI (phantom-deps): CLI ASCII art dep; resolved via workspace root in monorepo context. ai
phantom-deps phantom-dep:prisma AI (phantom-deps): Prisma CLI used for code generation via prebuild script; resolved via workspace. ai
phantom-deps phantom-dep:@inkjs/ui AI (phantom-deps): ink UI component dep; resolved via workspace root in monorepo context. ai
phantom-deps phantom-dep:ink-ascii AI (phantom-deps): ink ASCII dep; resolved via workspace root in monorepo context. ai
phantom-deps phantom-dep:@types/yargs AI (phantom-deps): Type definitions; framework-scoped, stable false positive. ai
phantom-deps phantom-dep:@prisma/client AI (phantom-deps): Prisma client generated at build time; resolved via workspace root. ai
phantom-deps phantom-dep:reflect-metadata AI (phantom-deps): Known implicit dep for decorators/tsyringe; loaded by convention. ai
phantom-deps phantom-dep:@envelop/extended-validation AI (phantom-deps): GraphQL plugin dep; resolved via workspace root in monorepo context. ai

Versions (showing 1 of 1)

Version Deps Published
0.2.0 11 / 14

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.