CodeSampleX

示例

verify pkg:npm/simple-update-notifier@2.0.0

sha256:de3fa6c379b5017d6828c2a5261af411e98e0c31fa578d14f4d47da2ef82a8ff

本网络只提供一件事:能构建的样本。它在沙箱中运行并保留签名回执。它不评级、不担保——同样的代码能否在你的环境构建,它没有测量过。 提交了通过的契约回执的不同签名密钥数量。为 1 表示只有作者;大于 1 表示还有其他人构建过。密钥是自行生成的,背后没有注册身份,因此计的是密钥而非人。 MIT-0

执行证据

声明的环境与签名的运行分开呈现,你可以看到这个样本究竟运行了什么、在哪里运行。

证据依据
签名契约通过
验证回执
1
构建过它的签名密钥
1
声明的环境 linux 24 · ubuntu · glibc 2.39 x64 npm

验证运行环境

环境 契约 阶段 运行日期
node 22 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1node:22-alpine@sha256:c610fcdfb1d5…
2026-08-28

案例

HOW
目标
verify pkg:npm/simple-update-notifier@2.0.0
创建时间
2026-08-28T04:52:59Z

契约

  1. simpleUpdateNotifier is an async function that checks for newer package versions from npm registry
  2. simpleUpdateNotifier opts out silently without network calls when stdout is not a TTY and alwaysRun is false
  3. simpleUpdateNotifier logs an update notification to stderr when a newer version is available and alwaysRun is true
  4. simpleUpdateNotifier persists lastUpdateCheck timestamp in XDG_CONFIG_HOME config directory
  5. simpleUpdateNotifier skips network check when last update check is within updateCheckInterval
  6. simpleUpdateNotifier does not log notification when latest registry version is equal to or older than current version
  7. simpleUpdateNotifier supports custom distTag parameter for targeting release tags like beta
  8. simpleUpdateNotifier catches network and parse errors gracefully without unhandled exceptions

文件

  • PROMPT.md
  • csx.json
  • package-lock.json
  • package.json
  • spec.json
  • src/index.js
  • test/contract.js

下载源代码构件 (tar.gz)

原始种子者

匿名