hypercore
51
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
mafintosh
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with holepunchto org's CI/CD practices. | ai | |
| provenance | slsa-provenance | AI (provenance): SLSA provenance attestation present; strongest supply chain integrity signal. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): lejeunerenard is a known contributor in the holepunchto ecosystem; addition is consistent with legitimate team growth for this active project. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Hypercore is a long-established package from its original maintainer mafintosh; dormancy followed by resumed development is consistent with the holepunchto ecosystem's release cadence. | ai | |
| dependencies | unvetted-dep:hypercore-storage | AI (dependencies): hypercore-storage is a first-party storage backend for hypercore, maintained by the same Holepunch organization. | ai | |
| dependencies | unvetted-dep:b4a | AI (dependencies): b4a is a well-known Buffer/Uint8Array compatibility library from the Holepunch ecosystem, stable and widely used across many P2P packages. | ai | |
| dependencies | unvetted-dep:streamx | AI (dependencies): streamx is a well-established streams implementation from the Holepunch/mafintosh ecosystem, used across many legitimate packages. | ai | |
| provenance | no-provenance | AI (provenance): hypercore is a long-established Holepunch ecosystem package; lack of provenance is consistent across all versions and is not a risk signal here. | ai | |
| phantom-deps | phantom-dep:bare-events | AI (phantom-deps): bare-events is intentionally declared in package.json imports for Bare runtime compatibility — a documented Holepunch ecosystem pattern, not a phantom dependency in the traditional sense. | ai |
Versions (showing 51 of 147)
| Version | Deps | Published |
|---|---|---|
| 11.35.0 | 21 / 14 | |
| 11.34.1 | 21 / 14 | |
| 11.34.0 | 21 / 14 | |
| 11.33.5 | 21 / 14 | |
| 11.33.2 | 21 / 14 | |
| 11.33.1 | 21 / 14 | |
| 11.33.0 | 21 / 14 | |
| 11.32.0 | 21 / 14 | |
| 11.31.0 | 21 / 14 | |
| 11.30.2 | 21 / 14 | |
| 11.30.1 | 21 / 14 | |
| 11.29.0 | 21 / 14 | |
| 11.28.1 | 21 / 14 | |
| 11.28.0 | 21 / 14 | |
| 11.27.17 | 21 / 14 | |
| 11.27.16 | 21 / 14 | |
| 11.27.15 | 21 / 14 | |
| 11.27.14 | 21 / 14 | |
| 11.27.13 | 21 / 14 | |
| 11.27.12 | 21 / 14 | |
| 11.27.11 | 21 / 14 | |
| 11.27.10 | 21 / 14 | |
| 11.27.9 | 21 / 14 | |
| 11.27.8 | 21 / 14 | |
| 11.27.7 | 21 / 14 | |
| 11.27.6 | 21 / 14 | |
| 11.27.5 | 21 / 14 | |
| 11.27.4 | 21 / 14 | |
| 11.27.3 | 21 / 14 | |
| 11.27.2 | 21 / 14 | |
| 11.27.1 | 21 / 14 | |
| 11.27.0 | 21 / 14 | |
| 11.26.0 | 21 / 14 | |
| 11.25.0 | 21 / 14 | |
| 11.24.0 | 21 / 14 | |
| 11.23.1 | 21 / 14 | |
| 11.23.0 | 21 / 14 | |
| 11.22.2 | 21 / 14 | |
| 11.22.1 | 21 / 14 | |
| 11.22.0 | 21 / 14 | |
| 11.21.7 | 21 / 14 | |
| 11.21.6 | 21 / 14 | |
| 11.21.5 | 21 / 14 | |
| 11.21.4 | 21 / 14 | |
| 11.21.2 | 21 / 14 | |
| 11.21.1 | 21 / 14 | |
| 11.21.0 | 21 / 14 | |
| 11.20.2 | 21 / 14 | |
| 11.20.1 | 21 / 14 | |
| 11.20.0 | 21 / 14 | |
| 11.19.1 | 21 / 14 |
v11.35.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.34.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.34.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.33.5
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.