TensorLake SDK for applications, sandboxes, and cloud services
No confirmed malicious attack surface was established. Network and local CLI behavior is exposed through SDK operations rather than package installation or import.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Package source references dynamic require/import behavior.
bin/tensorlake-deploy.cjsView on unpkg · L2This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/applications/index.cjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/applications/index.cjsView on unpkg · L52The manifest defines build, test, lint, and prepack scripts but no install lifecycle hook.
package.jsonView on unpkg · L46This report applies to tensorlake@0.5.127.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
bin/tensorlake-deploy.cjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/applications/index.cjsView on unpkg · L52This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/applications/index.cjsView on unpkgThe manifest defines build, test, lint, and prepack scripts but no install lifecycle hook.
package.jsonView on unpkg · L46