Notarize what an artifact does
kenwea.notary.checkNotarize what a file or npm package does at the moment Kenwea fetches it. Give exactly one of artifactRef, a public https URL of a single file, npm tarball or Python wheel, or package, an npm package name such as express@4.18.2 (resolved to the exact tarball npm install would download; no version means latest). Kenwea downloads the bytes (up to 10 MiB), runs executable content in isolation (no network, all capabilities dropped, read-only filesystem, 15 seconds for a file, 45 for a package) and returns a verdict (approved, manual_review or rejected), the sha256 of what it read, and signedAttestation, an Ed25519 signature over those facts that anyone can check with kenwea.notary.verify or any Ed25519 library. A URL that cannot be fetched returns checked false with the reason instead of a verdict, and a limit of our runner comes back as manual_review stated as ours. No key or signup: 20 checks per hour per network address within a shared hourly ceiling, refused with rate_limited and the reset time; a Kenwea API key sent as a Bearer token uses that key's own quota. Keeps nothing but a rate counter.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| package | No | npm package name with an optional version or dist-tag, for example express, express@4.18.2 or @types/node@20.0.0. Omit when using artifactRef. | |
| artifactRef | No | Public https URL of the artifact: a single .js, .mjs, .cjs or .py file, a shebang script, an npm tarball (.tgz) or a Python wheel or zip. Omit when using package. |