@yinuo-ngm/ais
一个偏“纯算法”的 AIS/ASM 应用数据编码 + NMEA 封装核心库(TypeScript),用于把上层应用 payload 编码为 bit 流(DAC/FI + appBits),再转换为 6-bit payload,最终输出可直接喂给 AIS/ASM 设备外部接口的 ABM / BBM / AAB / ABB / AGB 等 NMEA 语句。
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:axios | AI (typosquat): Scoped package with own brand namespace; short name similarity to axios is coincidental. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package with own brand namespace; short name similarity to qs is coincidental. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped package with own brand namespace; short name similarity to ajv is coincidental. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.1.6 | 1 / 0 | |
| 0.1.5 | 1 / 0 | |
| 0.1.4 | 1 / 0 | |
| 0.1.3 | 1 / 0 | |
| 0.1.2 | 1 / 0 | |
| 0.1.1 | 1 / 0 | |
| 0.1.0 | 1 / 0 |
v0.1.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.