Runtime application security for JavaScript and Node.js: dependency inventory, attack-surface mapping, and an in-process guard that virtually patches known vulnerabilities and hardens responses.
No confirmed malicious install-time or import-time attack surface was found. Reporting and project changes require explicit CLI or runtime configuration.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L275Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87This report applies to @patchstack/connect@0.5.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L275Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87