@whook/dev
Whook development dependencies.
7
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
nfroidure
Keywords
whookknifecycleRESTHTTPOpenAPIwebservicehandlerserverframework
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:ts-morph | AI (phantom-deps): ts-morph is a build/config dependency; correctly declared and used in metapak/build context. | ai | |
| dependencies | unvetted-dep:knifecycle | AI (dependencies): Core dependency of the whook ecosystem maintained by the same author. | ai | |
| dependencies | unvetted-dep:@whook/whook | AI (dependencies): Same monorepo package; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:common-services | AI (dependencies): Established companion package by same author. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped @whook/dev package; Levenshtein match to 'ajv' is a false positive with no real similarity. | ai | |
| dependencies | unvetted-dep:ya-open-api-types | AI (dependencies): OpenAPI types package in the same ecosystem; no risk signals. | ai | |
| dependencies | unvetted-dep:esbuild-node-externals | AI (dependencies): Popular esbuild utility plugin; well-known in the ecosystem. | ai | |
| dependencies | unvetted-dep:schema2dts | AI (dependencies): Known utility by same author; no risk signals. | ai |