← Home

@pylonsync/functions

TypeScript function runtime for pylon — defines server-side queries, mutations, and actions.

51
Versions
MIT OR Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ericc59

Keywords

pylontypescriptfunctionsdatabase

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): Package publishes very frequently (289 versions/73 days); expected cadence. ai
provenance missing-githead AI (provenance): Frequent automated releases; benign publish pipeline variance, no malicious payload. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Standard Proxy handler for touch-tracking, not evasion. ai
publish-pattern new-deps-added AI (publish-pattern): satori/resvg-wasm are well-known OG-image libs matching added SSR image feature. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode of PNG test fixtures in test file. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Test assertion data, not a real network call. ai
provenance no-provenance AI (provenance): Package has no install scripts or obfuscated code; provenance gap alone is not disqualifying for this package. ai

Versions (showing 51 of 316)

View all versions
Version Deps Published
0.3.346 2 / 6
0.3.345 2 / 6
0.3.344 2 / 6
0.3.343 2 / 6
0.3.342 2 / 6
0.3.341 2 / 6
0.3.340 2 / 6
0.3.339 2 / 6
0.3.338 2 / 6
0.3.337 2 / 6
0.3.336 2 / 6
0.3.335 2 / 6
0.3.334 2 / 6
0.3.333 2 / 6
0.3.332 2 / 6
0.3.331 2 / 6
0.3.330 2 / 6
0.3.329 2 / 6
0.3.328 2 / 6
0.3.327 2 / 6
0.3.326 2 / 6
0.3.324 2 / 6
0.3.323 2 / 6
0.3.322 2 / 6
0.3.321 2 / 6
0.3.320 2 / 6
0.3.319 2 / 6
0.3.318 2 / 6
0.3.317 0 / 6
0.3.316 0 / 6
0.3.315 0 / 6
0.3.314 0 / 6
0.3.312 0 / 6
0.3.311 0 / 6
0.3.310 0 / 6
0.3.309 0 / 6
0.3.308 0 / 6
0.3.307 0 / 6
0.3.306 0 / 6
0.3.305 0 / 6
0.3.304 0 / 6
0.3.303 0 / 6
0.3.302 0 / 6
0.3.301 0 / 6
0.3.300 0 / 6
0.3.299 0 / 6
0.3.298 0 / 6
0.3.297 0 / 6
0.3.296 0 / 6
0.3.295 0 / 6
0.3.294 0 / 6

v0.3.346

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.345

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.344

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.343

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.342

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.341

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.340

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.339

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.338

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.337

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.336

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.335

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.334

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.333

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.332

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.331

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.330

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.329

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.328

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.327

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.326

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.324

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.323

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.322

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.321

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.320

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.319

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.318

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:745 semgrep

HTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.317

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.316

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:745 semgrep

HTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.315

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:745 semgrep

HTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.314

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:745 semgrep

HTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.312

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:745 semgrep

HTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.311

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:745 semgrep

HTTP request to raw IP address — legitimate packages use domain names 743 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 744 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 745 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 746 | }); 747 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.310

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:744 semgrep

HTTP request to raw IP address — legitimate packages use domain names 742 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 743 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 744 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 745 | }); 746 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.309

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:696 semgrep

HTTP request to raw IP address — legitimate packages use domain names 694 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 695 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 696 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 697 | }); 698 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.308

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.307

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:696 semgrep

HTTP request to raw IP address — legitimate packages use domain names 694 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 695 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 696 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 697 | }); 698 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.306

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.305

2 findings
HIGH shady-links-raw-ip: src/ssr-runtime.test.ts:696 semgrep

HTTP request to raw IP address — legitimate packages use domain names 694 | expect(isSafeRedirect("https://checkout.stripe.com/pay/abc", trusted)).toBe(true); 695 | expect(isSafeRedirect("http://localhost:3000/x", trusted)).toBe(true); > 696 | expect(isSafeRedirect("http://127.0.0.1/x", trusted)).toBe(true); 697 | }); 698 |

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.304

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.303

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.302

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.301

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.300

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.299

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.298

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.297

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.296

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.