Don't deploy blind.
Check the release.
An independent checkpoint for CI/CD systems, package managers and deployment controllers. Inspect exact npm releases, verify published metadata and query known OSV vulnerabilities — without an AI model or a person at each execution.
Check a package now
This reads the public npm registry only. No payment is requested and it is not a vulnerability scan.
One verified-source report per release
$0.049 / request
Purchasers opt in explicitly. The paid report contacts npm + OSV, compares the buyer-pinned integrity value and returns evidence hashes, findings and a suggested hold/block/review decision.
Vendor the buyer integration →
Optional GitHub Actions lockfile trigger →
The example is not real verification. Actual paid calls require buyer-provided funding, consent and budget limits; unpaid requests receive HTTP 402. No seller-funded test charges.
Built for nonhuman buyers
Existing infrastructure can decide when a check is necessary and invoke it within a customer-owned payment policy.
Release pipelines
Checks before installation, automated deployments or dependency upgrades.
Software platforms
Admission checks on individual npm package versions before trusting a new dependency.
Unattended machines
Ordinary schedulers and build servers — no prompts, no chat sessions, no model tokens.
Integration contract
Free metadata lookup (caller-initiated and rate limited):
POST /v1/release-sentinel/quote
Content-Type: application/json
{"name":"lodash","version":"4.17.21","policy":{"block_on_vulnerability":true,"block_install_scripts":true}}
Optional paid live evidence, for explicitly authorized customers:
POST /v1/release-sentinel-evidence
Payment-Signature: <buyer-authorized x402 payment>
Content-Type: application/json
{"name":"lodash","version":"4.17.21"}
Or use POST /v1/prepaid/release-sentinel-evidence with an independently funded buyer API key, a unique Idempotency-Key and a X-Max-Credits ceiling.
Limitations: npm signature/provenance metadata is observed, not cryptographically verified; package tarballs are not downloaded, scanned or executed. OSV lists known disclosures and does not establish absence of malware or undisclosed flaws. Reports are source-derived observations, not signed independent security attestations.