@zintrust/core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode used for AES-256-GCM IV and auth tag parsing — legitimate crypto pattern. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall is a no-op process.exit(0); stable false positive for this package. | ai | |
| semgrep | semgrep:silent-process-exec | AI (semgrep): Detached spawn in VersionChecker is a self-restart pattern for CLI version upgrades, not a reverse shell. | ai | |
| semgrep | semgrep:silent-process-exec-var | AI (semgrep): Same VersionChecker self-restart context; benign for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get inside a Proxy get trap is idiomatic JS; not obfuscation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding JWT/auth token bodies in ServiceAuthMiddleware is standard auth middleware practice. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @zintrust/core is a framework, not a typosquat of cors; name collision is coincidental. | ai | |
| phantom-deps | phantom-dep:@zintrust/workers | AI (phantom-deps): Same-org sibling package loaded by framework convention. | ai | |
| phantom-deps | phantom-dep:@cloudflare/containers | AI (phantom-deps): Framework-scoped Cloudflare package loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:bullmq | AI (phantom-deps): bullmq is a declared dependency used via config/convention in this framework. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread passes process.env to a child process spawn — standard CLI framework pattern, not exfiltration. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All raw-IP references are localhost (127.0.0.1) log messages, not external network calls. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads process.env to build worker dev-vars config file — expected framework behavior. | ai |
Versions (showing 100 of 249)
| Version | Deps | Published |
|---|---|---|
| 3.0.9 | 13 / 0 | |
| 3.0.8 | 13 / 0 | |
| 3.0.7 | 13 / 0 | |
| 3.0.6 | 13 / 0 | |
| 3.0.5 | 13 / 0 | |
| 3.0.4 | 13 / 0 | |
| 3.0.3 | 13 / 0 | |
| 3.0.2 | 13 / 0 | |
| 3.0.1 | 13 / 0 | |
| 2.9.1 | 13 / 0 | |
| 2.9.0 | 13 / 0 | |
| 2.8.7 | 13 / 0 | |
| 2.8.6 | 13 / 0 | |
| 2.8.5 | 13 / 0 | |
| 2.8.4 | 13 / 0 | |
| 2.8.3 | 13 / 0 | |
| 2.8.2 | 12 / 0 | |
| 2.7.3 | 12 / 0 | |
| 2.7.2 | 12 / 0 | |
| 2.7.1 | 12 / 0 | |
| 2.5.9 | 12 / 0 | |
| 2.5.8 | 12 / 0 | |
| 2.5.7 | 12 / 0 | |
| 2.5.6 | 12 / 0 | |
| 2.5.5 | 12 / 0 | |
| 2.5.4 | 12 / 0 | |
| 2.5.3 | 12 / 0 | |
| 2.5.2 | 12 / 0 | |
| 2.5.1 | 12 / 0 | |
| 2.5.0 | 12 / 0 | |
| 2.4.9 | 12 / 0 | |
| 2.4.8 | 12 / 0 | |
| 2.4.7 | 12 / 0 | |
| 2.4.6 | 12 / 0 | |
| 2.4.5 | 12 / 0 | |
| 2.4.4 | 12 / 0 | |
| 2.4.3 | 12 / 0 | |
| 2.4.2 | 12 / 0 | |
| 2.4.0 | 12 / 0 | |
| 2.3.1 | 12 / 0 | |
| 2.3.0 | 12 / 0 | |
| 2.2.9 | 12 / 0 | |
| 2.2.8 | 12 / 0 | |
| 2.2.7 | 12 / 0 | |
| 2.2.6 | 12 / 0 | |
| 2.2.5 | 12 / 0 | |
| 2.2.4 | 12 / 0 | |
| 2.2.3 | 12 / 0 | |
| 2.2.2 | 12 / 0 | |
| 2.2.1 | 12 / 0 | |
| 2.2.0 | 12 / 0 | |
| 2.1.9 | 10 / 0 | |
| 2.1.8 | 10 / 0 | |
| 2.1.7 | 10 / 0 | |
| 2.1.6 | 10 / 0 | |
| 2.1.5 | 10 / 0 | |
| 2.1.4 | 10 / 0 | |
| 2.1.3 | 10 / 0 | |
| 2.1.2 | 10 / 0 | |
| 2.1.1 | 10 / 0 | |
| 2.1.0 | 10 / 0 | |
| 2.0.8 | 10 / 0 | |
| 2.0.7 | 10 / 0 | |
| 2.0.6 | 10 / 0 | |
| 2.0.5 | 10 / 0 | |
| 2.0.4 | 10 / 0 | |
| 2.0.3 | 10 / 0 | |
| 2.0.2 | 10 / 0 | |
| 2.0.1 | 10 / 0 | |
| 2.0.0 | 10 / 0 | |
| 1.8.6 | 10 / 0 | |
| 1.8.5 | 10 / 0 | |
| 1.8.4 | 10 / 0 | |
| 1.8.3 | 10 / 0 | |
| 1.8.2 | 10 / 0 | |
| 1.8.1 | 10 / 0 | |
| 1.8.0 | 10 / 0 | |
| 1.7.3 | 10 / 0 | |
| 1.7.2 | 10 / 0 | |
| 1.7.1 | 10 / 0 | |
| 1.7.0 | 10 / 0 | |
| 1.6.4 | 10 / 0 | |
| 1.6.3 | 10 / 0 | |
| 1.6.2 | 10 / 0 | |
| 1.6.1 | 10 / 0 | |
| 1.6.0 | 10 / 0 | |
| 1.5.5 | 10 / 0 | |
| 1.5.4 | 10 / 0 | |
| 1.5.3 | 10 / 0 | |
| 1.5.2 | 10 / 0 | |
| 1.5.1 | 10 / 0 | |
| 1.5.0 | 10 / 0 | |
| 1.2.0 | 10 / 0 | |
| 0.9.6 | 10 / 0 | |
| 0.9.5 | 10 / 0 | |
| 0.9.4 | 10 / 0 | |
| 0.9.3 | 10 / 0 | |
| 0.9.2 | 10 / 0 | |
| 0.9.1 | 10 / 0 | |
| 0.9.0 | 10 / 0 |
v3.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.