@sculptor/core
The SculptorTS core package boots the HTTP server and exposes the primary framework runtime API.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @sculptor/core is a scoped framework package, not a typosquat of cors; the name similarity is coincidental. | ai | |
| phantom-deps | phantom-dep:reflect-metadata | AI (phantom-deps): reflect-metadata is a well-known implicit dependency for TypeScript decorator metadata; not a real phantom dep. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 0.2.3 | 5 / 0 | |
| 0.2.2 | 5 / 0 | |
| 0.2.1 | 5 / 0 | |
| 0.2.0 | 5 / 0 | |
| 0.1.7 | 5 / 0 | |
| 0.1.6 | 5 / 0 | |
| 0.1.5 | 4 / 0 | |
| 0.1.4 | 4 / 0 | |
| 0.1.3 | 4 / 0 | |
| 0.1.2 | 4 / 0 | |
| 0.1.1 | 4 / 0 | |
| 0.1.0 | 4 / 0 |
v0.2.3
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.2
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.1
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.7
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
2 findingsPackage name '@sculptor/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.