Release Sentinel / npm Registry-OSV Gate
Live, independent npm dependency release risk evidence for non-AI package managers, CI/CD runners and deployment controllers. Check pinned sha512 integrity, lifecycle scripts, optional npm signature/provenance metadata and known OSV vulnerabilities before installing an exact package version. Live registry+OSV preflight runs prior to payment settlement, and errors prevent fulfillment; buyer authorization is required.
5 credits per call · $0.049 USDC with x402
Sample input
{
"name": "lodash",
"version": "4.17.21",
"policy": {
"block_on_vulnerability": true,
"block_install_scripts": true
}
}Worked sample output
{
"ok": true,
"mode": "release_sentinel_example",
"example_only": true,
"not_live": true,
"name": "lodash",
"version": "4.17.21",
"decision": "illustrative_only",
"warning": "Worked schema example, not live npm or OSV verification. Paid fulfillment runs independent source checks."
}Worked example using published sample data only. Own-data execution is paid.
Connect in curl
Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.
curl 'https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/release-sentinel-evidence' \
-H "Authorization: Bearer $BOUNTY_API_KEY" \
-H 'Content-Type: application/json' \
-H 'Idempotency-Key: workflow-request-001' \
-H 'X-Max-Credits: 5' \
--data '{"name":"lodash","version":"4.17.21","policy":{"block_on_vulnerability":true,"block_install_scripts":true}}'Connect in n8n
Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.
Use an HTTP POST to https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/release-sentinel-evidence. Send JSON and these headers; store the Bearer token as a private credential.
{
"method": "POST",
"headers": {
"Authorization": "Bearer YOUR_PRIVATE_API_KEY",
"Content-Type": "application/json",
"Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
"X-Max-Credits": "5"
},
"body": {
"name": "lodash",
"version": "4.17.21",
"policy": {
"block_on_vulnerability": true,
"block_install_scripts": true
}
}
}Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe