@symbo.ls/sdk
[](https://www.npmjs.com/package/@symbo.ls/sdk) [](https://www.npmjs.com/package/@symbo.ls/sdk) [ relied on exactly this gap.
Maintainers
nikolozatinyzajimlberiasvinchychejuichentokoyoungbaronsilverzacharybetzenbsachdevatthomasaggbneeli33locsymbols
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used in ordering.js expression evaluator with try/catch; consistent pattern for this SDK across versions. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv is a declared runtime dep used in config files; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:node-fetch | AI (phantom-deps): node-fetch is a declared runtime dep; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 3.14.1 | 15 / 10 |
v3.14.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.