← Home

@bobfrankston/msger

Fast, lightweight, cross-platform message box - Rust-powered alternative to msgview

43
Versions
ISC
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

bobfrankston

Keywords

message-boxdialogwebviewrustnativecross-platformtypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:base64-decode AI (semgrep): Decodes own render payload to write a local file, not payload hiding. ai
publish-pattern rapid-publish AI (publish-pattern): Publisher releases ~2 versions/day consistently; rapid publish is the normal cadence for this package. ai
bogus-package bogus-package AI (bogus-package): Scoped personal package with 347 versions and 3.8k downloads; sparse README/no repo URL is a style choice, not spam. ai
publish-pattern new-deps-added AI (publish-pattern): New dep @bobfrankston/msgcommon is under the same author namespace; low risk of supply-chain attack from same maintainer's scoped package. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall selects the appropriate prebuilt native binary for the platform — standard pattern for cross-platform native tools. Stable for this package. ai
semgrep semgrep:env-spread AI (semgrep): env-spread is in cruft/build.ts, a dev build script. Spreading process.env into execSync is standard build tooling practice, not a runtime exfiltration risk. ai
npm-metadata bundled-binaries AI (npm-metadata): Bundled binaries are the prebuilt Rust executables and Microsoft WebView2 runtime DLLs that are the core deliverable of this cross-platform native message box tool. Not backdoors. ai

Versions (showing 43 of 43)

Version Deps Published
0.1.404 4 / 1
0.1.402 4 / 1
0.1.400 4 / 1
0.1.383 4 / 1
0.1.381 4 / 1
0.1.366 3 / 1
0.1.362 3 / 1
0.1.350 3 / 1
0.1.224 3 / 1
0.1.222 3 / 1
0.1.211 3 / 1
0.1.199 3 / 1
0.1.186 3 / 1
0.1.183 3 / 1
0.1.180 3 / 1
0.1.175 3 / 1
0.1.170 3 / 1
0.1.167 3 / 1
0.1.166 3 / 1
0.1.164 3 / 1
0.1.162 3 / 1
0.1.161 3 / 1
0.1.160 3 / 1
0.1.159 3 / 1
0.1.148 2 / 1
0.1.63 0 / 1
0.1.44 0 / 1
0.1.32 0 / 1
0.1.16 0 / 1
0.1.15 0 / 1
0.1.14 0 / 1
0.1.12 0 / 1
0.1.11 0 / 1
0.1.10 0 / 1
0.1.9 0 / 1
0.1.8 0 / 1
0.1.7 0 / 1
0.1.6 0 / 1
0.1.5 0 / 1
0.1.4 0 / 1
0.1.3 0 / 1
0.1.2 0 / 1
0.1.1 0 / 1

v0.1.404

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.402

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.400

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.