@bemedev/core
The core library of @bemedev, providing essential functionalities and utilities for the Bemedev ecosystem.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; same author identity (chlbri) in package.json maintainers. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version bump from 0.5.0 to 1.3.0; large file count increase expected with significant library expansion. | ai | |
| provenance | missing-githead | AI (provenance): GitHub Actions CI publish flow may not inject gitHead; SLSA provenance attestation provides equivalent commit traceability. | ai | |
| source-diff | obfuscated-file:lib/.codebase.cjs | AI (source-diff): File is structured JSON metadata (codebase analysis output from @bemedev/codebase), not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:lib/.codebase.js | AI (source-diff): File is structured JSON metadata (codebase analysis output from @bemedev/codebase), not obfuscated malicious code. | ai | |
| npm-metadata | url-dep:cli | AI (npm-metadata): Self-referential file: dep for testing the package's own CLI; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): chokidar is a declared runtime dep used in CLI/watch tooling; phantom-dep heuristic misfires here. | ai | |
| phantom-deps | phantom-dep:@bemedev/sleep | AI (phantom-deps): Same-org dep; phantom-dep heuristic misfires for indirectly-imported utilities. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @bemedev/core is the core library of the bemedev ecosystem, not a typosquat of cors. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 1.5.0 | 6 / 24 | |
| 1.4.0 | 6 / 24 | |
| 1.3.1 | 6 / 24 | |
| 1.3.0 | 6 / 24 | |
| 1.2.0 | 6 / 24 | |
| 1.1.0 | 6 / 24 | |
| 1.0.0 | 6 / 24 | |
| 0.5.0 | 7 / 31 | |
| 0.4.4 | 7 / 31 | |
| 0.4.3 | 7 / 31 | |
| 0.4.2 | 7 / 31 | |
| 0.4.0 | 7 / 31 | |
| 0.3.1 | 6 / 33 | |
| 0.3.0 | 6 / 33 | |
| 0.2.0 | 5 / 34 | |
| 0.1.8 | 6 / 28 | |
| 0.1.7 | 6 / 28 | |
| 0.1.6 | 6 / 28 | |
| 0.1.5 | 6 / 28 | |
| 0.1.2 | 6 / 29 | |
| 0.1.1 | 6 / 30 | |
| 0.1.0 | 6 / 30 |
v1.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v1.3.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v1.3.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
This version was published by a different npm account than previous versions on 2026-07-02. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
This version was published by a different npm account than previous versions on 2026-07-02. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v1.0.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
This version was published by a different npm account than previous versions on 2026-07-01. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.