← Home

@thescaffold/ntx-flags

```ts the Ntx SDK to interact with the Flags API for logging and analytics. import { EventsService, FlagsModule } from '@thescaffold/ntx-flags';

17
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

isaiahiroko

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): All added deps are established NestJS/ecosystem packages; no malicious or unvetted packages introduced. ai
phantom-deps phantom-dep:@nestjs/terminus AI (phantom-deps): Scaffold library pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:@nestjs/throttler AI (phantom-deps): Scaffold library pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:class-transformer AI (phantom-deps): Scaffold library pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:@fastify/multipart AI (phantom-deps): Scaffold library pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:countly-sdk-nodejs AI (phantom-deps): Scaffold library pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:@nestjs/event-emitter AI (phantom-deps): Scaffold library pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:@thescaffold/jsx-core AI (phantom-deps): Same org scope; scaffold library pattern. ai
phantom-deps phantom-dep:@thescaffold/jsx-blobs AI (phantom-deps): Same org scope; scaffold library pattern. ai
phantom-deps phantom-dep:@thescaffold/jsx-polylog AI (phantom-deps): Same org scope; scaffold library pattern. ai
phantom-deps phantom-dep:@nestjs/jwt AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:@nestjs/core AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:ua-parser-js AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:@nestjs/axios AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:@sentry/nestjs AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:cron AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:@nestjs/typeorm AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:class-validator AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:@nestjs/passport AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:@nestjs/schedule AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:@nestjs/swagger AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:typeorm AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:bcryptjs AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:node-ssh AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:socket.io AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai
phantom-deps phantom-dep:geoip-lite AI (phantom-deps): Peer-dep pattern for NestJS scaffold; stable across versions. ai

Versions (showing 17 of 17)

Version Deps Published
0.2.51 32 / 0
0.2.48 32 / 0
0.2.46 32 / 0
0.2.45 32 / 0
0.2.43 32 / 0
0.2.39 32 / 0
0.2.38 32 / 0
0.2.37 32 / 0
0.2.35 32 / 0
0.2.34 32 / 0
0.2.33 32 / 0
0.2.32 32 / 0
0.2.31 32 / 0
0.2.30 32 / 0
0.2.21 5 / 0
0.2.20 5 / 0
0.0.10 5 / 0

v0.2.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.32

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: isaiahiroko.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.