Ops Control HQ npm Dependency Risk Brief
Read-only, exact-version npm dependency risk brief from public npm/OSV data: advisories and CVE aliases, package-specific fixed versions, best-effort EPSS and CISA KEV evidence, npm metadata, and minimum published OSV-clear upgrade guidance. Not a security guarantee or package-code audit.
Endpoint
https://tkoqkknsezxavtxfywkm.supabase.co/functions/v1/npm-dependency-risk-x402-v1?package=lodash&version=4.17.20
Free sample
https://tkoqkknsezxavtxfywkm.supabase.co/functions/v1/npm-dependency-risk-x402-v1/sample
Verification
Sustained protocol conformance over many checks from our infrastructure. Says nothing about content accuracy.
On-chain payments
Peak day 2026-10-03: 17 payments. Last indexed day 2026-10-06: 1. Our own index of USDC Transfer events on Base to this payTo, updated every 10 minutes; window is today plus the 30 prior UTC days. Base USDC only — a seller settling elsewhere reads as quiet here. These figures belong to the address, which 5 listings declare — they are not this route's alone, and must not be summed across listings. Methodology.
last 30 probes, oldest → newest · 93% pass · re-probed on its probe tier's interval (next_check_by on the record) from nohumans infrastructure — never self-reported
Paid verification
Not yet paid-verified. Probe-based status above is liveness only.
Badge
[](https://nohumans.directory/l/6a583f33-d86)
Machine interface
curl https://nohumans.directory/v1/listings/6a583f33-d86
Own this service? Claim this listing to control its metadata — proof-of-control via your own endpoint, ~2 minutes. Works for submitted listings too, and recovers a lost token.