Repository navigation
Scanly SDK v2.1.0 — Link Intelligence
New: Link Intelligence
- Optional
@scanly/url-safetypackage with local URL signals and IDN-aware normalization. - Reputation provider abstraction, Google Web Risk and lookup-only VirusTotal adapters.
- Hardened Node-only remote inspection: public-IP pinning, DNS/redirect revalidation, bounded response size and timeouts.
- Vendor-neutral, JSON-schema-validated LLM assistance with a maximum 20-point contribution.
- Deterministic scoring: threat-intelligence authority cannot be overridden by AI.
- Explicit privacy modes, hashed caching, single-flight deduplication, cancellation and stale-result suppression.
- Browser/server separation and a default-disabled, self-hostable demo endpoint.
Privacy and security
Barcode decoding remains local. No barcode image or camera frame is sent to reputation or AI providers. URL network analysis is explicit opt-in. No verdict guarantees a URL is safe; risk scores are composite heuristics, not probabilities. LLM output is advisory evidence, not an authority.
Compatibility
Existing v2 scanner APIs remain compatible. Native C/Swift/Kotlin APIs and the C ABI are unchanged apart from release version metadata. The iOS source package remains under native/ios; check out this exact tag and use that subdirectory with Swift Package Manager. Android AARs are distributed as GitHub Release assets, not through Maven Central.
Qualification and verified publication
Qualified product source: 6b017b53a4404f4feab776ac111b0ea9dacf2734.
Product tree: c72430a2ab0a2d47e7cd095325088f1e053a5c41.
The versioned manifest binds software/security/API evidence, independent byte-identical npm builds, verified CI provenance, two independent Native builds, final metadata reproducibility, production signing proof and the READY deployment of the qualified product source. Checksums and SBOM are attached.
All 11 packages are published at 2.1.0, and every latest tag, downloaded Registry tarball, and cryptographic provenance attestation has been verified against the exact frozen artifacts. The existing ten packages identify GitHub Actions OIDC publication run 34726283486; @scanly/url-safety identifies independently rebuilt and signed run 34754673547 and used owner-authorized interactive 2FA for its first genuine publication.
The new package's Trusted Publisher is now configured for Yangjunjie-Lin/Scanly / stable-npm-publish.yml, including permission for direct npm publish. The post-setup OIDC check verified successful HTTP 201 identity exchanges for all 11 packages, without publishing anything or storing npm credentials. Package-wide 2FA settings were not changed. This establishes the future automation path separately from the already verified first publication.
Published packages: @scanly/benchmark, @scanly/browser, @scanly/core, @scanly/engine-jsqr, @scanly/engine-zxing-cpp-wasm, @scanly/engine-zxing-js, @scanly/node, @scanly/parsers, @scanly/react, @scanly/scenario-schema, and @scanly/url-safety.
Signed annotated tag object: 18874fffe7380190ac36d01128ed69f8c6e0dd69, targeting release commit d825d32051514a69f07e545e5a52ad6a73cffef7; GitHub verifies the signature as valid. The immutable publication record captures Release ID 387738256, all 27 asset digests, Registry identities, and the verified READY production deployment.
The initial URL Safety submission was rejected because npm requires the first provenance dependency to match the signing certificate's workflow source. The additive correction record preserves that failure and binds two fresh independent builds, 11 byte-identical tarballs, and 22 verified proofs. The actual product source remains explicitly recorded. No tag, frozen manifest, original proof, or artifact was replaced. The standalone THIRD_PARTY_NOTICES asset has CRLF checkout bytes with identical signed-tag text; the other 26 assets match exact signed-tag file bytes.
Automated validation is not physical-device qualification. Issue #13 remains open and independent, with physical-device validation pending. v2.0.0 and v2.0.1 tags, records and artifacts remain immutable.
Final closeout
SCANLY_LINK_INTELLIGENCE_GO / SCANLY_V2_1_0_RELEASE_GO.
The final release-tooling CI passed 876 tests across 106 files and 84 Playwright smoke tests, with unchanged coverage thresholds. Protected PRs #61 and #63 finalized publication records and their integrity checks; PR #62 synchronized main into develop. Final main is 22e2751b04118b5a6ad97340909997852a8bd4ec, and develop is bd5b10cbe1e698aa639c5b85cbb8e7f54e607730: identical file trees with distinct normal merge commits. The signed release tag continues to target d825d32051514a69f07e545e5a52ad6a73cffef7.
The final remote check re-downloaded all 31 npm tarballs across 2.0.0, 2.0.1, and 2.1.0, verified the current 11 attestations, preserved the original 27 Release assets, and confirmed the final-main production deployment is READY with HTTP 200. See the complete acceptance report and machine-readable closeout snapshot.