@astral-sh/ruff-wasm-web
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): Expected wasm-bindgen compiled artifact for this wasm binding package. | ai | |
| provenance | missing-githead | AI (provenance): Offset by SLSA/Sigstore provenance from trusted GitHub Actions publisher. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard wasm-bindgen generated glue code; Reflect.get is idiomatic in WASM JS bindings. | ai | |
| bogus-package | bogus-package | AI (bogus-package): WASM binary package with no deps by design; README links to official docs; not spam. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 0.16.0 | 0 / 0 | |
| 0.15.22 | 0 / 0 | |
| 0.15.21 | 0 / 0 | |
| 0.15.20 | 0 / 0 | |
| 0.15.19 | 0 / 0 | |
| 0.15.18 | 0 / 0 | |
| 0.15.17 | 0 / 0 | |
| 0.15.16 | 0 / 0 | |
| 0.15.15 | 0 / 0 | |
| 0.15.14 | 0 / 0 | |
| 0.15.13 | 0 / 0 | |
| 0.15.12 | 0 / 0 | |
| 0.15.11 | 0 / 0 | |
| 0.15.10 | 0 / 0 | |
| 0.15.9 | 0 / 0 | |
| 0.15.8 | 0 / 0 | |
| 0.15.7 | 0 / 0 | |
| 0.15.6 | 0 / 0 | |
| 0.15.5 | 0 / 0 | |
| 0.15.4 | 0 / 0 | |
| 0.15.3 | 0 / 0 | |
| 0.15.2 | 0 / 0 | |
| 0.15.1 | 0 / 0 | |
| 0.15.0 | 0 / 0 | |
| 0.14.14 | 0 / 0 | |
| 0.14.13 | 0 / 0 | |
| 0.14.11 | 0 / 0 | |
| 0.14.10 | 0 / 0 | |
| 0.14.9 | 0 / 0 | |
| 0.14.8 | 0 / 0 | |
| 0.14.7 | 0 / 0 | |
| 0.14.6 | 0 / 0 | |
| 0.6.4 | 0 / 0 |
v0.16.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.22
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.21
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.10
4 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (crmarsh) on 2026-04-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.15.9
4 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (crmarsh) on 2026-04-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.15.8
4 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (crmarsh) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.15.7
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.6
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.5
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.4
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.3
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.2
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.1
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.0
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.14
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.13
3 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: crmarsh.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.11
2 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.10
2 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.9
2 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.8
2 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.7
2 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.6
2 findingsPackage contains compiled binaries that could be backdoors: • ruff_wasm_bg.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.