@superblocksteam/ai-service-templates
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Internal scoped package from established org; missing description is cosmetic. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs the same build script as the build command; standard codegen pattern for this org's packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped package from established org; missing metadata is cosmetic, not indicative of malice. | ai |
Versions (showing 51 of 77)
| Version | Deps | Published |
|---|---|---|
| 2.0.118 | 0 / 2 | |
| 2.0.117 | 0 / 2 | |
| 2.0.116 | 0 / 2 | |
| 2.0.115 | 0 / 2 | |
| 2.0.114 | 0 / 2 | |
| 2.0.112 | 0 / 2 | |
| 2.0.110 | 0 / 2 | |
| 2.0.108 | 0 / 2 | |
| 2.0.106 | 0 / 2 | |
| 2.0.105 | 0 / 2 | |
| 2.0.104 | 0 / 2 | |
| 2.0.103 | 0 / 2 | |
| 2.0.102 | 0 / 2 | |
| 2.0.101 | 0 / 2 | |
| 2.0.98 | 0 / 2 | |
| 2.0.97 | 0 / 2 | |
| 2.0.95 | 0 / 2 | |
| 2.0.94 | 0 / 2 | |
| 2.0.92 | 0 / 2 | |
| 2.0.89 | 0 / 2 | |
| 2.0.88 | 0 / 2 | |
| 2.0.87 | 0 / 2 | |
| 2.0.86 | 0 / 2 | |
| 2.0.85 | 0 / 2 | |
| 2.0.83 | 0 / 2 | |
| 2.0.81 | 0 / 2 | |
| 2.0.80 | 0 / 3 | |
| 2.0.78 | 0 / 3 | |
| 2.0.76 | 0 / 3 | |
| 2.0.75 | 0 / 3 | |
| 2.0.73 | 0 / 3 | |
| 2.0.71 | 0 / 3 | |
| 2.0.68 | 0 / 3 | |
| 2.0.66 | 0 / 3 | |
| 2.0.65 | 0 / 3 | |
| 2.0.64 | 0 / 3 | |
| 2.0.63 | 0 / 3 | |
| 2.0.60 | 0 / 3 | |
| 2.0.58 | 0 / 3 | |
| 2.0.56 | 0 / 3 | |
| 2.0.55 | 0 / 3 | |
| 2.0.54 | 0 / 3 | |
| 2.0.52 | 0 / 3 | |
| 2.0.51 | 0 / 3 | |
| 2.0.50 | 0 / 3 | |
| 2.0.49 | 0 / 3 | |
| 2.0.41 | 0 / 3 | |
| 2.0.40 | 0 / 3 | |
| 2.0.39 | 0 / 3 | |
| 2.0.38 | 0 / 3 | |
| 2.0.37 | 0 / 3 |
v2.0.118
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.117
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.116
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.115
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.114
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.112
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.110
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.108
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.106
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.105
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.104
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.103
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.102
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.101
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.98
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.97
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.95
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.94
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.92
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.89
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.88
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.87
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.86
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.85
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.83
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.81
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.80
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.78
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.76
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.75
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.73
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.71
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.68
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.66
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.65
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.64
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.63
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.60
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.58
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.56
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.55
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.54
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.52
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.51
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.50
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.49
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.41
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.40
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.39
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.38
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.37
2 findingsScript: node ./scripts/build.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.