@rsdoctor/sdk
This package is the intermediate data layer of Rsdoctor.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:launch-editor | AI (dependencies): launch-editor is a well-known editor-opener utility used by webpack-dev-server; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Webpack bundle of legitimate deps (body-parser, cors, etc.); stable pattern for this package's bundled build. | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): Webpack bundle of legitimate deps; stable pattern for this package's bundled build. | ai | |
| source-diff | obfuscated-file:compiled/dayjs/index.js | AI (source-diff): Minified dayjs library compiled into package; expected for bundled distribution. | ai | |
| source-diff | net-exec-file:dist/index.cjs | AI (source-diff): Network+exec pattern is from bundled server deps (body-parser, socket.io); not malicious. | ai | |
| source-diff | net-exec-file:dist/index.js | AI (source-diff): Network+exec pattern is from bundled server deps (body-parser, socket.io); not malicious. | ai | |
| provenance | publisher-changed | AI (provenance): chenjiahan → GitHub Actions is a legitimate CI automation transition confirmed by SLSA provenance attestation. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/fs-extra | AI (phantom-deps): Type-only dep used at build time; framework-scoped convention, stable false positive. | ai | |
| dependencies | unvetted-dep:@rsdoctor/graph | AI (dependencies): Sibling monorepo package at matching version; not an independent risk. | ai | |
| dependencies | unvetted-dep:@rsdoctor/types | AI (dependencies): Sibling monorepo package at matching version; not an independent risk. | ai | |
| dependencies | unvetted-dep:@rsdoctor/utils | AI (dependencies): Sibling monorepo package at matching version; not an independent risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package; sparse README and no keywords are typical for internal SDK packages. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 1.6.1 | 8 / 15 | |
| 1.6.0 | 8 / 15 | |
| 1.5.18 | 8 / 15 | |
| 1.5.17 | 8 / 15 | |
| 1.5.16 | 8 / 15 | |
| 1.5.15 | 8 / 15 | |
| 1.5.14 | 8 / 15 | |
| 1.5.13 | 8 / 15 | |
| 1.5.12 | 8 / 15 | |
| 1.5.11 | 8 / 15 | |
| 1.5.10 | 8 / 15 | |
| 1.5.7 | 8 / 15 | |
| 1.5.6 | 8 / 15 | |
| 1.5.3 | 8 / 15 | |
| 1.5.2 | 7 / 15 | |
| 1.5.1 | 7 / 15 | |
| 1.5.0 | 7 / 15 | |
| 1.4.0 | 7 / 15 | |
| 1.3.16 | 7 / 15 | |
| 1.3.15 | 7 / 15 | |
| 1.3.14 | 7 / 15 | |
| 1.3.13 | 7 / 15 | |
| 1.3.12 | 7 / 15 | |
| 1.3.11 | 7 / 15 | |
| 1.3.10 | 7 / 15 | |
| 1.3.9 | 7 / 15 | |
| 1.3.8 | 7 / 15 | |
| 1.3.7 | 7 / 15 | |
| 1.3.6 | 7 / 15 | |
| 1.3.5 | 7 / 15 | |
| 1.3.4 | 7 / 15 | |
| 1.3.3 | 7 / 15 | |
| 1.3.2 | 7 / 15 | |
| 1.3.1 | 7 / 15 | |
| 1.3.0 | 7 / 15 | |
| 1.1.10 | 16 / 6 | |
| 1.1.8 | 16 / 6 | |
| 1.1.1 | 16 / 6 | |
| 1.0.2 | 16 / 6 | |
| 1.0.1 | 16 / 6 | |
| 1.0.0 | 16 / 6 |
v1.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.