@demica/shared

v99.99.100

Published

Authorized benign dependency-confusion canary for FIS Bugcrowd testing.

Downloads

468

Readme

@demica/shared

Authorized benign dependency-confusion canary for FIS Bugcrowd testing.

This package performs a single postinstall HTTP ping to the tester-controlled collector. The package code does not read or transmit environment variables, usernames, working directories, filesystem contents, command output, credentials, tokens, or source code.

The collector records only network/request metadata visible to the server: source IP, User-Agent, timestamp, package name, package version, nonce, and lifecycle phase. Version 99.99.100 also sends os.hostname() for program-requested attribution.