← Home

@astral-sh/ruff-wasm-web

33
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

datenmetzgerxcrmarshzanie-astral-sh

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): Expected wasm-bindgen compiled artifact for this wasm binding package. ai
provenance missing-githead AI (provenance): Offset by SLSA/Sigstore provenance from trusted GitHub Actions publisher. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Standard wasm-bindgen generated glue code; Reflect.get is idiomatic in WASM JS bindings. ai
bogus-package bogus-package AI (bogus-package): WASM binary package with no deps by design; README links to official docs; not spam. ai

Versions (showing 33 of 33)

Version Deps Published
0.16.0 0 / 0
0.15.22 0 / 0
0.15.21 0 / 0
0.15.20 0 / 0
0.15.19 0 / 0
0.15.18 0 / 0
0.15.17 0 / 0
0.15.16 0 / 0
0.15.15 0 / 0
0.15.14 0 / 0
0.15.13 0 / 0
0.15.12 0 / 0
0.15.11 0 / 0
0.15.10 0 / 0
0.15.9 0 / 0
0.15.8 0 / 0
0.15.7 0 / 0
0.15.6 0 / 0
0.15.5 0 / 0
0.15.4 0 / 0
0.15.3 0 / 0
0.15.2 0 / 0
0.15.1 0 / 0
0.15.0 0 / 0
0.14.14 0 / 0
0.14.13 0 / 0
0.14.11 0 / 0
0.14.10 0 / 0
0.14.9 0 / 0
0.14.8 0 / 0
0.14.7 0 / 0
0.14.6 0 / 0
0.6.4 0 / 0

v0.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.22

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.21

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.10

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: crmarsh → GitHub Actions (on 2026-04-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (crmarsh) on 2026-04-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.15.9

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: crmarsh → GitHub Actions (on 2026-04-02, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (crmarsh) on 2026-04-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.15.8

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: crmarsh → GitHub Actions (on 2026-03-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (crmarsh) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.15.7

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.6

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.5

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.4

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.3

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.2

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.1

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.14

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.13

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.11

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.10

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.9

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.8

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.7

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.6

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.