← Home

@serve.zone/remoteingress

Edge ingress tunnel for DcRouter - tunnels TCP and UDP traffic from the network edge to SmartProxy over TLS or QUIC, preserving client IP via PROXY protocol.

2
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

lossless

Keywords

remote accessingress tunnelnetwork edgePROXY protocolmultiplexed tunnelTCP proxyTLS tunnelserve.zone stackTypeScriptRustSmartProxy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): Package explicitly builds and ships Rust binaries (tsrust build step); linux amd64/arm64 binaries are the expected output. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode is standard JWT/token parsing (Buffer.from → JSON.parse); no obfuscation or exfiltration pattern. ai
phantom-deps phantom-dep:@push.rocks/qenv AI (phantom-deps): @push.rocks/qenv is a declared runtime dependency; phantom-dep heuristic false positive for this package. ai

Versions (showing 2 of 2)

Version Deps Published
4.17.1 3 / 7
4.17.0 3 / 7

v4.17.1

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist_rust/remoteingress-bin_linux_amd64 • dist_rust/remoteingress-bin_linux_arm64

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.17.0

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist_rust/remoteingress-bin_linux_amd64 • dist_rust/remoteingress-bin_linux_arm64

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.