@babel/plugin-proposal-private-property-in-object
This plugin transforms checks for a private property in an object
18
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
hzooexistentialismnicolo-ribaudojlhwung
Keywords
babel-plugin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Babel monorepo publishing workflow variation; trusted publisher nicolo-ribaudo with extensive track record. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 704B→4KB is trivial absolute growth for an actively developed Babel plugin gaining implementation code. | ai | |
| bogus-package | bogus-package | AI (bogus-package): All three signals are false positives for @babel/* packages: mass production is the Babel monorepo pattern, tiny payload is normal for plugin wrappers, and inflated semver reflects Babel's lockstep versioning strategy. | ai | |
| provenance | no-provenance | AI (provenance): Official Babel monorepo package published by a long-standing core team member; lack of provenance is not a meaningful risk signal for this package. | ai | |
| dependencies | unvetted-dep:@babel/plugin-syntax-private-property-in-object | AI (dependencies): Official @babel scoped package from the same monorepo; unvetted status is a registry artifact, not a real risk. | ai | |
| dependencies | unvetted-dep:@babel/helper-annotate-as-pure | AI (dependencies): Official @babel scoped package from the same monorepo; unvetted status is a registry artifact, not a real risk. | ai | |
| dependencies | unvetted-dep:@babel/helper-create-class-features-plugin | AI (dependencies): Official @babel scoped package from the same monorepo; unvetted status is a registry artifact, not a real risk. | ai |