redis-memory-server
8
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
mhassan1
Keywords
redismockstubredis-prebuilt
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Established package with 263k weekly downloads; long gap between releases is plausible for a stable utility. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): uuid is a declared runtime dependency; phantom-dep heuristic false positive for this package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used for binary extraction/execution — core functionality of a binary-download test-server package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall downloads Redis prebuilt binaries — documented and expected for this test-server package. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): semver is a declared runtime dependency; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads user-supplied config provider path — documented config resolution pattern for this package. | ai | |
| semgrep | semgrep:dll-hijacking-commands | AI (semgrep): msiexec usage is for extracting Redis Windows installer, not DLL hijacking; stable false positive for this package. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 0.17.0 | 12 / 31 | |
| 0.16.1 | 13 / 31 | |
| 0.16.0 | 14 / 32 | |
| 0.15.1 | 15 / 33 | |
| 0.15.0 | 15 / 33 | |
| 0.14.1 | 15 / 34 | |
| 0.14.0 | 15 / 34 | |
| 0.13.0 | 15 / 34 |
v0.17.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.