{"_id":"@assurly/scanner-core","_rev":"9-c8e5eef886a4d4511834a91638308bef","name":"@assurly/scanner-core","dist-tags":{"latest":"1.2.2"},"versions":{"1.0.0":{"name":"@assurly/scanner-core","version":"1.0.0","keywords":["static-analysis","security","ship-gate","nextjs","supabase","stripe","vercel","rls","code-scanner"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.0.0","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://github.com/assurly/assurly/issues"},"dist":{"shasum":"d2efffc9f246930e1ffef6ab540c8083cfeb9080","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.0.0.tgz","fileCount":17,"integrity":"sha512-3jqag/Bewio6EXqqzquGzcXxaDHJbmWsXM43hRrwfZRFO0UY0B804NftiJU2KgmNCIq2TZ9RT1m7Ve51ZsNZ/A==","signatures":[{"sig":"MEUCIQCZgNxeBNoZOJWlTWFdAONsophcNbqILUfd0gdDPVMrswIgOlv4yFoxXNDXFAay1ONaEKLoeuO2FgiI1RQu6zeF9ps=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@assurly%2fscanner-core@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":95846},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":">=20.9"},"gitHead":"0c9b239855921573b36f3f44af4ae23579837052","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Browser-safe static analysis rules shared by Assurly surfaces","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.0.0_1783533523979_0.09393392487099139","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@assurly/scanner-core","version":"1.0.1","keywords":["static-analysis","security","ship-gate","nextjs","supabase","stripe","vercel","rls","code-scanner"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.0.1","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://github.com/assurly/assurly/issues"},"dist":{"shasum":"434ae67fdbfbefee95be25d0326f1b4fed1fa4f6","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.0.1.tgz","fileCount":17,"integrity":"sha512-50QkCeufEnklqp0sIOAMBpvktDgLpT9MWc2HA+LYiMSwGsEQi+iR5z7cSIQZ92lG6b7IcZK/mTxzKYMBG8U6mg==","signatures":[{"sig":"MEYCIQDNtxnmgRneJj2XMpqRd9C+epcN8vFIogMxiMnRigrltQIhALPk0voi13hZut6OjANfTG3K19a47ogpqiJ81Jr2UN0l","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@assurly%2fscanner-core@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":95876},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":">=20.9"},"gitHead":"8d26cfba60f1ac2479fc47771c3f4c4eb3e20aa2","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Browser-safe static analysis rules shared by Assurly surfaces","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.0.1_1783535119741_0.99370965196244","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@assurly/scanner-core","version":"1.0.2","keywords":["static-analysis","security","ship-gate","nextjs","supabase","stripe","vercel","rls","code-scanner"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.0.2","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://github.com/assurly/assurly/issues"},"dist":{"shasum":"04b2f839d3be8d91c7e6bd9c1565e8aecee0d2e9","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.0.2.tgz","fileCount":17,"integrity":"sha512-xVpGInbgtLDSguakUdI1zikFFoatZF8wE3SMrASHoRBoymcZG/MIZK8xxdIXx6pAlGp6fk8boxhd+IuwIj6JXQ==","signatures":[{"sig":"MEUCICOCvrTQ0Pqg//iCRslFT7pOoxk9GSaVkDFtQry7Wu7lAiEA0+FeFgm83PyMiPXV4xT4AsYS+EVGsCkIVJs1TDU8zDo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@assurly%2fscanner-core@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":95876},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":">=20.9"},"gitHead":"ac2021c0dc3907932e0a3aa7ce8eaf02c9a4e3d4","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Browser-safe static analysis rules shared by Assurly surfaces","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.0.2_1783546104704_0.850479655596698","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@assurly/scanner-core","version":"1.0.3","keywords":["static-analysis","security","ship-gate","nextjs","supabase","stripe","vercel","rls","code-scanner","ai-generated-code","sast","security-rules"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.0.3","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"dist":{"shasum":"bf486680b51c4e0da0832d3fc203a2ff312bcae2","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.0.3.tgz","fileCount":18,"integrity":"sha512-bOGbXVD1FVgr4jJ5BVAKixEUKuVRKToM0vYMCKlaQFgc3GJy7SCAGYU1WG8GVRQpI02LPhu43PLd8GGhtUC20A==","signatures":[{"sig":"MEQCIEJDzPsH58/1BE1oKiwy69+qrRL4Z/B+8QuOLl5v905VAiBWfwxdySa5MYmmPphkg1w4NDBFrdaBHslt//THpri5ow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":97623},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"4ed08c94dadc62eea014c42244b2e587ff8ee0c3","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Static analysis rules that catch what breaks AI-built SaaS in production — missing Supabase RLS, unverified Stripe webhooks, leaked service keys. Runs in Node or the browser.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.0.3_1784667045649_0.6411419180794533","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@assurly/scanner-core","version":"1.0.4","keywords":["static-analysis","security","ship-gate","nextjs","supabase","stripe","vercel","rls","code-scanner","ai-generated-code","sast","security-rules"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.0.4","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"dist":{"shasum":"864b4a1d977ef3d36badcdd7127516f10510b1d9","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.0.4.tgz","fileCount":18,"integrity":"sha512-Tbss2Kr5RgyTOhExSo+9nMSPU0ZT54Bl/hGeRFCK59Kfob925FQPskTZpjNWJTfbQAgiCX954x0/NgLX15Qxqw==","signatures":[{"sig":"MEUCIEXWPJ3o5ScwW0aIkxZaINrd3PjrGq00LP98r7YkXlphAiEAp+DZGmNTcJrinauWkyxe7Nv86IWlQbxxWCyuHeDly18=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":97876},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"86ef4045166751457648e824d87ed904c97bbb5e","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Static analysis rules that catch what breaks AI-built SaaS in production — missing Supabase RLS, unverified Stripe webhooks, leaked service keys. Runs in Node or the browser.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.0.4_1784710751989_0.057064087335685354","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@assurly/scanner-core","version":"1.1.0","keywords":["static-analysis","security","ship-gate","nextjs","supabase","stripe","vercel","rls","code-scanner","ai-generated-code","sast","security-rules"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.1.0","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"dist":{"shasum":"c10a0981038105c1963295e416d0a245c0f50e86","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.1.0.tgz","fileCount":32,"integrity":"sha512-9lN7wEwh9VgDOkCTvFU4Tjn4RSgaRL1mYCk6yKgGRlTrP+jINO4NvuQex5VXAIBaLtTZ1VM2KZxU72aMjBMIFw==","signatures":[{"sig":"MEUCIED0f4auukMwgCU+DNHqe+STOJYgkxyvp0nTbcLUSH6gAiEAzPf+K8V95m1VW8l+WWKqb5pzCvGkXGvoMfxufhyjOYg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":272757},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"2dafa4820f891f38ef25caa10fc8eb633ea6410f","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Static analysis rules that catch what breaks AI-built SaaS in production — missing Supabase RLS, unverified Stripe webhooks, leaked service keys. Runs in Node or the browser.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.1.0_1785092241168_0.2501827850151048","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@assurly/scanner-core","version":"1.2.0","keywords":["static-analysis","security","ship-gate","nextjs","supabase","stripe","vercel","rls","code-scanner","ai-generated-code","sast","security-rules"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.2.0","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"dist":{"shasum":"ce79fd5f1b9bbfe0f5c7d290d50d59c5c4ed8838","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.2.0.tgz","fileCount":34,"integrity":"sha512-tLwUlXESiJvzy3GPHWfcgukVdlPasWz7W7U3wi4IQJv1ddW2yRUIKmU+qRs1TQvO6r8bERmjbi8l0yjMPZomzg==","signatures":[{"sig":"MEUCIQDy0vAKf0iACbnybOwbSqwCylF4CFIsUQA9c1r4JFHrpgIgJeB3n7G2DRls+Y0I/ocRd+6tRcNpbKVYR4rOWcufDes=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":306706},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"7e7ac0b90c2100de2fefe1a60ddd3a79809f9c49","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Static analysis rules that catch what breaks AI-built SaaS in production — missing Supabase RLS, unverified Stripe webhooks, leaked service keys. Runs in Node or the browser.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.2.0_1785130897449_0.20706419050917457","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@assurly/scanner-core","version":"1.2.1","keywords":["allowscripts","install-scripts","postinstall","npm12","supply-chain-security","dependency-audit","lockfile","slopsquat","typosquat","mcp-security","agent-security","prompt-injection","static-analysis","security-rules","security-scanner","sast","ship-gate","code-scanner","nextjs","supabase","stripe","vercel","rls","ai-generated-code"],"author":{"name":"Assurly"},"license":"MIT","_id":"@assurly/scanner-core@1.2.1","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"homepage":"https://assurly.dev","bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"dist":{"shasum":"ede074ef59926002fbfa9976f023aadf8f16922e","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.2.1.tgz","fileCount":34,"integrity":"sha512-q15LRVWxBZOpnmnciqLM4k3ryL9ufa08/ydlg0NMc4pJlnZFdKz4iluIML9+F2//8oMeBIKA/EYSoaF+FL8ukA==","signatures":[{"sig":"MEUCIQD7omRCq+1r0jOg2VjXVwgHmuAsI6TrxgVtBRnqed5DbQIgAs8O7YHTnsOuqFdRssAX1fuCxR5Gv1b/gSB6MErEL8w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":309775},"main":"dist/index.js","type":"commonjs","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"f1cfd6916f4becbed2159eb3efb1043396ee1197","scripts":{"test":"vitest run src","build":"tsc -p tsconfig.json","prepack":"npm run build && npm test"},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"repository":{"url":"git+https://github.com/assurly/assurly.git","type":"git","directory":"packages/scanner-core"},"_npmVersion":"10.9.8","description":"Offline static-analysis rules behind Assurly: npm 12 install-script trust (allowScripts), MCP agent config auditing, slopsquat detection, Supabase RLS, Stripe webhooks, leaked service keys. Runs in Node or the browser.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@babel/types":"^7.28.5","@babel/parser":"^7.28.5"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^5.3.3"},"_npmOperationalInternal":{"tmp":"tmp/scanner-core_1.2.1_1785139715972_0.5284226654046749","host":"s3://npm-registry-packages-npm-production"}},"1.2.2":{"name":"@assurly/scanner-core","version":"1.2.2","description":"Offline static-analysis rules behind Assurly: npm 12 install-script trust (allowScripts), MCP agent config auditing, slopsquat detection, Supabase RLS, Stripe webhooks, leaked service keys. Runs in Node or the browser.","keywords":["allowscripts","install-scripts","postinstall","npm12","supply-chain-security","dependency-audit","lockfile","slopsquat","typosquat","mcp-security","agent-security","prompt-injection","static-analysis","security-rules","security-scanner","sast","ship-gate","code-scanner","nextjs","supabase","stripe","vercel","rls","ai-generated-code"],"homepage":"https://assurly.dev","license":"MIT","author":{"name":"Assurly"},"type":"commonjs","main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || >=22.12.0"},"repository":{"type":"git","url":"git+https://github.com/assurly/assurly.git","directory":"packages/scanner-core"},"scripts":{"build":"tsc -p tsconfig.json","test":"vitest run src","prepack":"npm run build && npm test"},"dependencies":{"@babel/parser":"^7.28.5","@babel/types":"^7.28.5"},"devDependencies":{"typescript":"^5.3.3","vitest":"^4.1.8"},"publishConfig":{"access":"public"},"bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"_id":"@assurly/scanner-core@1.2.2","gitHead":"24077ed38d474a7b516177500f4fd33c7b006b11","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-KplnZEBB2KDN5dpxuZfGWzfU/E0e4W7AyIbRK8LS53Q29obtdWbgAKvAsUd/JZLq6p2+cufQ5yxxakFXhbeB2Q==","shasum":"efa9cb45647c5e2de9d51a0bfb98311afda15005","tarball":"https://registry.npmjs.org/@assurly/scanner-core/-/scanner-core-1.2.2.tgz","fileCount":34,"unpackedSize":310107,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEyi3NEcGWm+1jxPvx5P5XNGDxcpqSS8vPODcZgw3TMGAiEAlWMHmEWvjISiv69y3j+Li+qwNXT0UZR+gaej9h3ScNM="}]},"_npmUser":{"name":"tibco87","email":"tkutik72@gmail.com"},"directories":{},"maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/scanner-core_1.2.2_1785428168603_0.3791414175203902"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-08T17:58:43.843Z","modified":"2026-07-30T16:16:09.032Z","1.0.0":"2026-07-08T17:58:44.156Z","1.0.1":"2026-07-08T18:25:19.875Z","1.0.2":"2026-07-08T21:28:24.844Z","1.0.3":"2026-07-21T20:50:45.853Z","1.0.4":"2026-07-22T08:59:12.116Z","1.1.0":"2026-07-26T18:57:21.318Z","1.2.0":"2026-07-27T05:41:37.616Z","1.2.1":"2026-07-27T08:08:36.108Z","1.2.2":"2026-07-30T16:16:08.809Z"},"bugs":{"url":"https://assurly.dev/#contact","email":"support@assurly.dev"},"author":{"name":"Assurly"},"license":"MIT","homepage":"https://assurly.dev","keywords":["allowscripts","install-scripts","postinstall","npm12","supply-chain-security","dependency-audit","lockfile","slopsquat","typosquat","mcp-security","agent-security","prompt-injection","static-analysis","security-rules","security-scanner","sast","ship-gate","code-scanner","nextjs","supabase","stripe","vercel","rls","ai-generated-code"],"repository":{"type":"git","url":"git+https://github.com/assurly/assurly.git","directory":"packages/scanner-core"},"description":"Offline static-analysis rules behind Assurly: npm 12 install-script trust (allowScripts), MCP agent config auditing, slopsquat detection, Supabase RLS, Stripe webhooks, leaked service keys. Runs in Node or the browser.","maintainers":[{"name":"tibco87","email":"tkutik72@gmail.com"}],"readme":"# @assurly/scanner-core\n\nThe browser-safe static-analysis engine behind [Assurly](https://assurly.dev) — the rules that decide whether a Next.js + Supabase + Stripe + Vercel app is ready to ship. Shared by the web scanner, the CLI, the GitHub integration, and the MCP server so every surface produces the same Ship Gate verdict.\n\n> **Most people don't install this directly.** If you want to _run_ a scan, use one of these instead:\n>\n> - **CLI:** [`assurly`](https://www.npmjs.com/package/assurly) — `npx assurly scan --path .`\n> - **AI agents (Cursor / Claude Code):** [`@assurly/mcp-server`](https://www.npmjs.com/package/@assurly/mcp-server) — see [assurly.dev/mcp](https://assurly.dev/mcp)\n>\n> This package is the reusable rule engine those tools are built on.\n\n## In short\n\n`@assurly/scanner-core` is the offline rule engine behind Assurly. It exports pure\nfunctions that take file contents and return findings, with no filesystem access, no\nnetwork calls and no telemetry, so the same rules run in Node and in a browser. Coverage\nspans Supabase row-level security, Stripe webhook signature verification, secrets reaching\nclient bundles, React Server Component leaks, SQL migration safety, connection pooling,\nedge-runtime compatibility, cold starts, AI agent configuration (MCP client configs and\ninstruction files), and install-time trust under npm 12 — the `allowScripts` allowlist,\nlockfile packages that declare install scripts, and non-registry dependencies. Every rule\ncarries a confidence level so a gate can separate near-certain blockers from heuristics.\n\n## What it does\n\nEach rule carries an honest **confidence** so the Ship Gate can separate the three states that matter:\n\n- **Blockers** — high-confidence, high-impact issues you must fix before deploying (e.g. a Supabase table with RLS disabled, a Stripe webhook without signature verification, a live secret in the bundle).\n- **Review** — heuristic findings worth a look, never a hard stop.\n- **Warnings** — lower-severity noise you can usually ship past.\n\nDetection is intentionally **precise over exhaustive**: a rule that can't be defended to a senior engineer in 30 seconds is not a blocker.\n\n> **Static rules stay high-trust and few.** Prefer raising precision of the existing gate over growing\n> the rulebook. Net-new static surfaces (e.g. install-time trust / `supply-*`) are exceptions when they\n> audit a durable local trust artefact with zero network and clear false-positive discipline. Depth\n> otherwise comes from the runtime probe and the AI layer.\n\n## Can these rules run in a browser?\n\nYes. Every export is a pure function that takes file contents as a string and returns\nfindings — no `fs`, no `child_process`, no network client. That is why the same rule set\nbacks the web dashboard, the CLI, the GitHub integration and the MCP server, and why a scan\nin one surface matches a scan in another on the same project.\n\n## What does a rule's confidence mean?\n\nConfidence is the rule's own estimate of how certain the finding is, and it is what decides\nwhether something can stop a deploy:\n\n> Only an `error` finding with `high` confidence can become a blocker. Everything else lands\n> in review or warnings. A rule that cannot be defended to a senior engineer in thirty\n> seconds does not get to block a deploy, because a gate that cries wolf is switched off,\n> and a gate that is switched off protects nothing.\n\nTwo categories never block at all, whatever their severity: `agent-*` and `supply-*`. Those\naudit the developer's own tooling rather than the application being deployed.\n\n## What does it check for Supabase, Stripe and npm?\n\n- **Supabase** — tables created without [row-level\n  security](https://supabase.com/docs/guides/database/postgres/row-level-security), policies\n  that grant unrestricted access via `USING (true)`, and service-role keys reachable from\n  client code.\n- **Stripe** — webhook endpoints that never call\n  [`constructEvent`](https://docs.stripe.com/webhooks#verify-official-libraries) to verify\n  the signature, missing idempotency, and live keys in development env files.\n- **npm** — the [`allowScripts`\n  allowlist](https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/)\n  introduced when npm 12 stopped running install scripts by default, lockfile packages that\n  declare install scripts, and non-registry dependencies.\n\n## Does it send anything anywhere?\n\nNo. The package makes no network requests and collects no telemetry. It has no filesystem\naccess either — callers read files and pass in the contents, which is what keeps it\nbrowser-safe.\n\n## Usage\n\n```ts\nimport { scanSqlMigration, buildShipGateReport } from '@assurly/scanner-core';\n\nconst { findings } = scanSqlMigration(sqlSource, 'supabase/migrations/init.sql');\nconst report = buildShipGateReport(findings, { scannedFileCount: 1, cleanFileCount: 0 });\n\nconsole.log(report.status); // 'blocked' | 'review' | 'ready'\nconsole.log(report.shipScore); // 0–100\n```\n\nThe package is browser-safe (no Node-only imports), so the same rules run in the web dashboard and on the server.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}