datastand.dev/api/data/npm-vuln-digest
1.Catalog declaration
| Resource URL | https://datastand.dev/api/data/npm-vuln-digest |
| Source | cdp_bazaar |
| Declared method | GET |
| Network | eip155:8453 |
| Receiving address | 0x470a1b647d668d3820add26d70c8371557ff4c6b |
| Declared price (base units) | 20000 |
| Catalog status | active |
| First seen / last seen | 2026-08-15 01:37 UTC / 2026-09-29 01:03 UTC |
| Catalog-reported calls / payers (30d) | 3 / 3 |
2.Probe history
| Probed at | Method | Verdict | HTTP | Latency | Reason |
|---|---|---|---|---|---|
| 2026-09-28 22:40 UTC | GET | pass | 402 | 249 ms | — |
| 2026-09-28 04:40 UTC | GET | pass | 402 | 325 ms | — |
| 2026-09-27 13:40 UTC | GET | pass | 402 | 19 ms | — |
| 2026-09-26 16:40 UTC | GET | pass | 402 | 42 ms | — |
| 2026-09-25 22:40 UTC | GET | pass | 402 | 149 ms | — |
| 2026-09-25 04:40 UTC | GET | pass | 402 | 110 ms | — |
| 2026-09-24 13:40 UTC | GET | pass | 402 | 75 ms | — |
| 2026-09-23 16:40 UTC | GET | pass | 402 | 212 ms | — |
| 2026-09-23 04:40 UTC | GET | pass | 402 | 404 ms | — |
| 2026-09-20 11:24 UTC | GET | pass | 402 | 72 ms | — |
| 2026-09-17 12:35 UTC | GET | pass | 402 | 290 ms | — |
| 2026-09-14 11:24 UTC | GET | pass | 402 | 127 ms | — |
| 2026-09-10 11:24 UTC | GET | pass | 402 | 156 ms | — |
| 2026-09-06 11:24 UTC | GET | pass | 402 | 53 ms | — |
| 2026-09-01 23:14 UTC | GET | pass | 402 | 430 ms | — |
3.L1 — real purchases
1 of 1 paid attempts settled with a receipt, and 1 of those also returned a 2xx response (delivered). Each settled row carries its on-chain transaction hash — the receipt is the evidence. A settled row reads as nonce-bound when the on-chain re-read also matched the one-time signature nonce we generated for that purchase, and amount + payee when it matched amount, payee, asset and chain with no nonce on record — the binding shipped on 2026-09-04, so earlier rows carry the weaker evidence and keep their label rather than being demoted (methodology). settled is the transfer we confirmed on-chain; delivered is the response arriving. A settled row whose paid request answered 5xx counts as settled and not as delivered — definitions.
Terms in this table
settled (nonce-bound)- vet402 confirmed the USDC transfer on-chain, and the on-chain re-read also matched the one-time nonce vet402 signed for that purchase.
L2 mismatch- the response lacked fields the listing's output schema declares.
Whose side- the same words as the seller page: seller's side only after failures on two different days (UTC), marked “under re-check”; vet402's side; or not sorted (the rules).
| Attempted at | Result | HTTP | Receipt (tx) | Latency |
|---|---|---|---|---|
| 09-23 06:002026-09-23 06:00 UTC | settled (nonce-bound) | 200 | 0x553384e3…95f0 | 945 ms |
| 20000 units (≈ $0.02 USDC) · L2 mismatchWhose side: no failure (delivered) | ||||
Embed this record
Run this endpoint? Show the settle-through record vet402 measured — the badge reads 1/1 settled · 1 delivered and updates as the record grows. It carries the host it is about and the date it was last measured, so a saved copy cannot pass itself off as current. It states a measurement, not a rating.
[](https://vet402.com/observatory/e/88130a1b-f3a9-4c2f-8590-a379b5f3b500)4.Catalog listing events
No listing changes observed.
unverified is not a failure; a fail is published only after two consecutive failing probes. Definitions: methodology.
5.Dispute this record
Think a measurement above is wrong? Say which probe or purchase and what you observed instead. One person reads it and replies. The record is never deleted on dispute: if it was wrong, the correction is published with the same weight; if it was right, it stands. Operators who control the receiving address can also sign a dispute via POST /api/v1/observatory/disputes (API reference), which re-measures through the normal publication gate.
About the purchase at 2026-09-23T06:00:51Z (UTC). The form starts with that time; add what you saw instead.