@vybestack/llxprt-code-core
LLxprt Code Core
30
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
acoliver
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@ast-grep/lang-kotlin | AI (phantom-deps): Language plugin declared for optional use; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ast-grep/lang-csharp | AI (phantom-deps): Language plugin declared for optional use; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ast-grep/lang-swift | AI (phantom-deps): Language plugin declared for optional use; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ast-grep/lang-scala | AI (phantom-deps): Language plugin declared for optional use; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ast-grep/lang-php | AI (phantom-deps): Language plugin declared for optional use; stable pattern for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): tree-sitter-bash and web-tree-sitter are established, benign parsing libraries appropriate for this code-analysis package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Actively developed core library; large file additions are expected as features grow, no malicious indicators. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): ajv-formats is a plugin for ajv (which is a direct dep); plugin-style loading means it won't appear as a direct import. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-csharp | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-c | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-cpp | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-go | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-java | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-json | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-kotlin | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-php | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-python | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-ruby | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-rust | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-scala | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| dependencies | unvetted-dep:@ast-grep/lang-swift | AI (dependencies): ast-grep language grammar packages are legitimate open-source packages; expected for a code analysis tool. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Package has 360 versions, 282 days history, real GitHub repo, and 1.6k weekly downloads. README link density is documentation, not a link farm. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): execa is a legitimate process execution library; phantom detection is a false positive for this compiled TypeScript package. | ai | |
| phantom-deps | phantom-dep:@types/html-to-text | AI (phantom-deps): @types/* packages are type-only and never directly imported at runtime; phantom detection is expected and benign. | ai | |
| phantom-deps | phantom-dep:@types/glob | AI (phantom-deps): @types/* packages are type-only and never directly imported at runtime; phantom detection is expected and benign. | ai | |
| phantom-deps | phantom-dep:https-proxy-agent | AI (phantom-deps): https-proxy-agent is a legitimate proxy library; phantom detection is a false positive for this compiled TypeScript package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-logs-otlp-grpc | AI (phantom-deps): OpenTelemetry exporters are commonly loaded conditionally/dynamically; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-logs-otlp-http | AI (phantom-deps): OpenTelemetry exporters are commonly loaded conditionally/dynamically; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-grpc | AI (phantom-deps): OpenTelemetry exporters are commonly loaded conditionally/dynamically; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-http | AI (phantom-deps): OpenTelemetry exporters are commonly loaded conditionally/dynamically; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-metrics-otlp-grpc | AI (phantom-deps): OpenTelemetry exporters are commonly loaded conditionally/dynamically; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-metrics-otlp-http | AI (phantom-deps): OpenTelemetry exporters are commonly loaded conditionally/dynamically; phantom detection is a false positive for this package. | ai | |
| dependencies | unvetted-dep:fast-levenshtein | AI (dependencies): fast-levenshtein is a well-known, widely-used string distance library with no known security issues; appropriate for an AI coding assistant. | ai | |
| dependencies | unvetted-dep:@lvce-editor/ripgrep | AI (dependencies): @lvce-editor/ripgrep is a ripgrep binary wrapper used in VS Code-like editors; appropriate and expected for a code assistant core library. | ai | |
| phantom-deps | phantom-dep:micromatch | AI (phantom-deps): micromatch is a legitimate glob matching library; phantom detection is a false positive for this compiled TypeScript package. | ai | |
| phantom-deps | phantom-dep:mnemonist | AI (phantom-deps): mnemonist is a legitimate data structures library; phantom detection is a false positive for this compiled TypeScript package. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a legitimate WebSocket library; phantom detection is a false positive for this compiled TypeScript package with conditional/dynamic imports. | ai | |
| phantom-deps | phantom-dep:fast-uri | AI (phantom-deps): fast-uri is a legitimate URI library; phantom detection is a false positive for this compiled TypeScript package. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv is a legitimate env-loading library; phantom detection is a false positive for this compiled TypeScript package. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 0.9.3 | 69 / 12 | |
| 0.9.2 | 69 / 12 | |
| 0.9.1 | 69 / 12 | |
| 0.9.0 | 69 / 12 | |
| 0.8.1 | 54 / 12 | |
| 0.8.0 | 54 / 12 | |
| 0.7.0 | 52 / 13 | |
| 0.6.1 | 47 / 13 | |
| 0.6.0 | 47 / 13 | |
| 0.5.0 | 45 / 13 | |
| 0.4.8 | 45 / 13 | |
| 0.4.7 | 45 / 13 | |
| 0.4.6 | 45 / 13 | |
| 0.3.4 | 45 / 13 | |
| 0.2.25 | 40 / 13 | |
| 0.2.24 | 40 / 13 | |
| 0.2.3 | 40 / 13 | |
| 0.2.2 | 40 / 13 | |
| 0.1.23 | 40 / 12 | |
| 0.1.22 | 35 / 11 | |
| 0.1.21 | 35 / 11 | |
| 0.1.20 | 35 / 11 | |
| 0.1.19 | 35 / 11 | |
| 0.1.18 | 34 / 9 | |
| 0.1.17 | 32 / 7 | |
| 0.1.16 | 32 / 7 | |
| 0.1.15 | 31 / 7 | |
| 0.1.14 | 31 / 7 | |
| 0.1.13 | 28 / 7 | |
| 0.1.12 | 26 / 7 |