@saltcorn/server
Server app for Saltcorn, open-source no-code platform
4
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
tanielsenchristianhugoch
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@aws-sdk/s3-request-presigner | AI (phantom-deps): Framework-scoped AWS SDK package loaded by convention; stable false positive. | ai | |
| source-diff | encoded-string-file:docs/assets/navigation.js | AI (source-diff): TypeDoc-generated navigation data; base64/deflate compressed navigation tree, not a malicious payload. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): pg is a core DB dependency referenced via config/convention in this framework package. | ai | |
| phantom-deps | phantom-dep:pluralize | AI (phantom-deps): Stable false positive; used via config/convention in this framework. | ai | |
| phantom-deps | phantom-dep:tmp-promise | AI (phantom-deps): Stable false positive; used via config/convention in this framework. | ai | |
| phantom-deps | phantom-dep:@socket.io/sticky | AI (phantom-deps): Stable false positive; loaded by convention in cluster config. | ai | |
| phantom-deps | phantom-dep:@saltcorn/sbadmin2 | AI (phantom-deps): Same-org monorepo sibling; loaded by plugin convention. | ai | |
| phantom-deps | phantom-dep:content-disposition | AI (phantom-deps): Stable false positive; used via config/convention in this framework. | ai | |
| source-diff | encoded-string-file:docs/assets/hierarchy.js | AI (source-diff): TypeDoc-generated navigation data; base64/deflate compressed hierarchy tree, not a malicious payload. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads locale JSON files by name from a controlled directory — not arbitrary module loading. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside bundled Monaco editor loader.js — standard pattern in the Monaco editor bundle. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): Eval used to execute data-on-cloned attribute callbacks in DOM — expected no-code platform behavior. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Used in restart_watcher.js for server restart functionality — legitimate server management use. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Fetches localhost (127.0.0.1) for systemd watchdog health check — not an exfiltration endpoint. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established platform package; README link dump and empty auth/index.js are artifacts of monorepo structure. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): @saltcorn/server is a scoped package for the Saltcorn platform, not a typosquat of semver. | ai |