@pylonsync/functions
TypeScript function runtime for pylon — defines server-side queries, mutations, and actions.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Package publishes very frequently (289 versions/73 days); expected cadence. | ai | |
| provenance | missing-githead | AI (provenance): Frequent automated releases; benign publish pipeline variance, no malicious payload. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard Proxy handler for touch-tracking, not evasion. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): satori/resvg-wasm are well-known OG-image libs matching added SSR image feature. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode of PNG test fixtures in test file. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Test assertion data, not a real network call. | ai | |
| provenance | no-provenance | AI (provenance): Package has no install scripts or obfuscated code; provenance gap alone is not disqualifying for this package. | ai |
Versions (showing 51 of 316)
| Version | Deps | Published |
|---|---|---|
| 0.3.346 | 2 / 6 | |
| 0.3.345 | 2 / 6 | |
| 0.3.344 | 2 / 6 | |
| 0.3.343 | 2 / 6 | |
| 0.3.342 | 2 / 6 | |
| 0.3.341 | 2 / 6 | |
| 0.3.340 | 2 / 6 | |
| 0.3.339 | 2 / 6 | |
| 0.3.338 | 2 / 6 | |
| 0.3.337 | 2 / 6 | |
| 0.3.336 | 2 / 6 | |
| 0.3.335 | 2 / 6 | |
| 0.3.334 | 2 / 6 | |
| 0.3.333 | 2 / 6 | |
| 0.3.332 | 2 / 6 | |
| 0.3.331 | 2 / 6 | |
| 0.3.330 | 2 / 6 | |
| 0.3.329 | 2 / 6 | |
| 0.3.328 | 2 / 6 | |
| 0.3.327 | 2 / 6 | |
| 0.3.326 | 2 / 6 | |
| 0.3.324 | 2 / 6 | |
| 0.3.323 | 2 / 6 | |
| 0.3.322 | 2 / 6 | |
| 0.3.321 | 2 / 6 | |
| 0.3.320 | 2 / 6 | |
| 0.3.319 | 2 / 6 | |
| 0.3.318 | 2 / 6 | |
| 0.3.317 | 0 / 6 | |
| 0.3.316 | 0 / 6 | |
| 0.3.315 | 0 / 6 | |
| 0.3.314 | 0 / 6 | |
| 0.3.312 | 0 / 6 | |
| 0.3.311 | 0 / 6 | |
| 0.3.310 | 0 / 6 | |
| 0.3.309 | 0 / 6 | |
| 0.3.308 | 0 / 6 | |
| 0.3.307 | 0 / 6 | |
| 0.3.306 | 0 / 6 | |
| 0.3.305 | 0 / 6 | |
| 0.3.304 | 0 / 6 | |
| 0.3.303 | 0 / 6 | |
| 0.3.302 | 0 / 6 | |
| 0.3.301 | 0 / 6 | |
| 0.3.300 | 0 / 6 | |
| 0.3.299 | 0 / 6 | |
| 0.3.298 | 0 / 6 | |
| 0.3.297 | 0 / 6 | |
| 0.3.296 | 0 / 6 | |
| 0.3.295 | 0 / 6 | |
| 0.3.294 | 0 / 6 |
v0.3.346
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.345
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.344
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.343
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.342
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.341
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.340
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.339
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.338
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.337
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.336
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.335
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.334
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.333
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.332
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.331
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.330
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.329
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.328
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.327
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.326
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.324
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.323
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.322
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.321
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.320
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.319
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.318
2 findingsHTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.317
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.316
2 findingsHTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.315
2 findingsHTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.314
2 findingsHTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.312
2 findingsHTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.311
2 findingsHTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.310
2 findingsHTTP request to raw IP address — legitimate packages use domain names 742 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 743 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 744 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 745 | }); 746 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.309
2 findingsHTTP request to raw IP address — legitimate packages use domain names 694 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 695 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 696 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 697 | }); 698 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.308
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.307
2 findingsHTTP request to raw IP address — legitimate packages use domain names 694 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 695 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 696 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 697 | }); 698 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.306
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.305
2 findingsHTTP request to raw IP address — legitimate packages use domain names 694 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 695 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 696 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 697 | }); 698 |
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.304
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.303
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.302
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.301
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.300
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.299
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.298
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.297
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.296
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.