fhirpath
16
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
plynchnlmyury-sedinkin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:benny | AI (npm-metadata): benny is a devDependency benchmark tool; SHA-pinned commit is a dev workflow artifact, not a runtime supply-chain risk. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Rebuilds benny devDep from a pinned git commit to fix a known issue; documented, benign, stable pattern for this package. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Preinstall runs bin/install-demo.js, a demo-setup helper documented in the HL7 fhirpath.js repo; stable pattern for this package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used only in demo install helper, not in runtime library code; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): js-yaml is a declared runtime dep used in config/CLI tooling; phantom-dep heuristic misfires here. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander is used in the CLI bin entry; phantom-dep heuristic misfires here. | ai |