BOUNTY ENGINEER / RELEASE SENTINEL
Machine-native trust infrastructure

Don't deploy blind.
Check the release.

An independent checkpoint for CI/CD systems, package managers and deployment controllers. Inspect exact npm releases, verify published metadata and query known OSV vulnerabilities — without an AI model or a person at each execution.

No agent neededLive npm registryOSV advisoriesNo automatic buyer enrollment
LIVE DATA · FREE METADATA QUOTE

Check a package now

This reads the public npm registry only. No payment is requested and it is not a vulnerability scan.

DEEP SOURCE EVIDENCE

One verified-source report per release

$0.049 / request

Purchasers opt in explicitly. The paid report contacts npm + OSV, compares the buyer-pinned integrity value and returns evidence hashes, findings and a suggested hold/block/review decision.

Paid API contract →

Illustrative JSON example →

Vendor the buyer integration →

Optional GitHub Actions lockfile trigger →

The example is not real verification. Actual paid calls require buyer-provided funding, consent and budget limits; unpaid requests receive HTTP 402. No seller-funded test charges.

Built for nonhuman buyers

Existing infrastructure can decide when a check is necessary and invoke it within a customer-owned payment policy.

Release pipelines

Checks before installation, automated deployments or dependency upgrades.

Software platforms

Admission checks on individual npm package versions before trusting a new dependency.

Unattended machines

Ordinary schedulers and build servers — no prompts, no chat sessions, no model tokens.

Integration contract

Free metadata lookup (caller-initiated and rate limited):

POST /v1/release-sentinel/quote
Content-Type: application/json

{"name":"lodash","version":"4.17.21","policy":{"block_on_vulnerability":true,"block_install_scripts":true}}

Optional paid live evidence, for explicitly authorized customers:

POST /v1/release-sentinel-evidence
Payment-Signature: <buyer-authorized x402 payment>
Content-Type: application/json

{"name":"lodash","version":"4.17.21"}

Or use POST /v1/prepaid/release-sentinel-evidence with an independently funded buyer API key, a unique Idempotency-Key and a X-Max-Credits ceiling.

Limitations: npm signature/provenance metadata is observed, not cryptographically verified; package tarballs are not downloaded, scanned or executed. OSV lists known disclosures and does not establish absence of malware or undisclosed flaws. Reports are source-derived observations, not signed independent security attestations.