@bemedev/dev-utils
A collection of utilities for Node.js development, including build tools, testing utilities, and configuration management.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:oxc-transform | AI (phantom-deps): Used in config files, not a direct import; benign build tool usage. | ai | |
| provenance | missing-githead | AI (provenance): CI publish attestation present; gitHead gap is metadata noise, not a behavior signal. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-tsc-alias | AI (phantom-deps): Used in rollup config, not direct import; expected for build-tool package. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-tsconfig-paths | AI (phantom-deps): Used in rollup config, not direct import; expected for build-tool package. | ai | |
| dependencies | unvetted-dep:rollup-plugin-tsc-alias | AI (dependencies): Legitimate rollup plugin for TSC alias resolution; appropriate for a dev-utils build tooling package. | ai | |
| dependencies | unvetted-dep:rollup-plugin-circular-dependencies | AI (dependencies): Legitimate rollup plugin for circular dependency detection; appropriate for a dev-utils build tooling package. | ai | |
| provenance | publisher-changed | AI (provenance): GitHub Actions publisher is backed by SLSA Sigstore attestation; legitimate CI/CD transition for this package. | ai | |
| provenance | no-provenance | AI (provenance): Small dev-utils package; lack of provenance is common and no other risk signals present. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 1.0.2 | 10 / 12 | |
| 1.0.1 | 11 / 12 | |
| 1.0.0 | 11 / 12 | |
| 0.8.3 | 10 / 9 | |
| 0.8.2 | 10 / 9 | |
| 0.8.1 | 10 / 9 | |
| 0.8.0 | 10 / 24 | |
| 0.7.0 | 10 / 24 | |
| 0.6.11 | 10 / 24 | |
| 0.6.10 | 10 / 24 | |
| 0.6.9 | 10 / 24 | |
| 0.6.8 | 10 / 24 | |
| 0.6.7 | 10 / 24 | |
| 0.6.6 | 10 / 24 | |
| 0.6.5 | 10 / 24 | |
| 0.6.4 | 10 / 27 | |
| 0.6.3 | 10 / 27 | |
| 0.6.2 | 10 / 27 | |
| 0.6.1 | 10 / 26 | |
| 0.6.0 | 10 / 26 | |
| 0.5.3 | 10 / 26 | |
| 0.5.2 | 10 / 26 | |
| 0.5.1 | 10 / 26 | |
| 0.5.0 | 10 / 26 | |
| 0.4.0 | 10 / 26 | |
| 0.3.2 | 10 / 26 | |
| 0.3.1 | 10 / 26 | |
| 0.1.2 | 10 / 26 | |
| 0.1.1 | 10 / 30 | |
| 0.1.0 | 10 / 30 |
v1.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.