@budibase/string-templates
Handlebars wrapper for Budibase templating.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Plain atob/base64 utility helper, no payload delivery. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval used for template/snippet caching, not remote code execution. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Stale unremoved publish over 193d indicates legitimate change, not compromise. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same transition context; not a takeover pattern. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Publisher stable for 193d with strong track record; consistent with org transition. | ai | |
| provenance | publisher-changed | AI (provenance): christos-budibase is an established Budibase org publisher; internal team rotation, not a takeover signal. | ai | |
| phantom-deps | phantom-dep:lodash.clonedeep | AI (phantom-deps): Declared and used; phantom-dep heuristic is imperfect for bundled/re-exported deps. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Budibase monorepo with 3112 versions; org publisher account; no content changes from prior approved version. | ai | |
| dependencies | unvetted-dep:@budibase/vm-browserify | AI (dependencies): Same org scope (@budibase); internal dependency stable across Budibase monorepo versions. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): handlebars is a well-known templating library; pinned to 4.7.9 which is the latest stable release. | ai | |
| phantom-deps | phantom-dep:@budibase/vm-browserify | AI (phantom-deps): Same-org scoped dep; likely bundled via rollup rather than directly imported. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal Budibase monorepo package; sparse README and missing metadata are expected for scoped internal packages. | ai | |
| phantom-deps | phantom-dep:@budibase/handlebars-helpers | AI (phantom-deps): Same-org scoped dep; likely bundled via rollup rather than directly imported. | ai |
Versions (showing 51 of 331)
| Version | Deps | Published |
|---|---|---|
| 3.40.1 | 4 / 11 | |
| 3.40.0 | 4 / 11 | |
| 3.39.32 | 4 / 11 | |
| 3.39.31 | 4 / 11 | |
| 3.39.30 | 4 / 11 | |
| 3.39.29 | 4 / 11 | |
| 3.39.28 | 4 / 11 | |
| 3.39.15 | 4 / 11 | |
| 3.38.5 | 4 / 11 | |
| 3.38.4 | 4 / 11 | |
| 3.38.3 | 4 / 11 | |
| 3.38.2 | 4 / 11 | |
| 3.38.1 | 4 / 11 | |
| 3.38.0 | 4 / 11 | |
| 3.37.5 | 4 / 11 | |
| 3.37.4 | 4 / 11 | |
| 3.37.3 | 4 / 11 | |
| 3.37.2 | 4 / 11 | |
| 3.37.1 | 4 / 11 | |
| 3.37.0 | 4 / 11 | |
| 3.36.5 | 4 / 11 | |
| 3.36.3 | 4 / 11 | |
| 3.36.1 | 4 / 11 | |
| 3.35.3 | 4 / 11 | |
| 3.35.2 | 4 / 11 | |
| 3.35.1 | 4 / 11 | |
| 3.35.0 | 4 / 11 | |
| 3.34.11 | 4 / 11 | |
| 3.34.10 | 4 / 11 | |
| 3.34.9 | 4 / 11 | |
| 3.34.8 | 4 / 11 | |
| 3.34.7 | 4 / 11 | |
| 3.34.6 | 4 / 11 | |
| 3.34.5 | 4 / 11 | |
| 3.34.4 | 5 / 11 | |
| 3.34.3 | 5 / 11 | |
| 3.34.2 | 5 / 11 | |
| 3.34.1 | 5 / 11 | |
| 3.34.0 | 5 / 11 | |
| 3.33.5 | 5 / 11 | |
| 3.33.4 | 5 / 11 | |
| 3.33.2 | 5 / 11 | |
| 3.33.1 | 5 / 11 | |
| 3.33.0 | 5 / 11 | |
| 3.32.6 | 5 / 11 | |
| 3.32.5 | 5 / 11 | |
| 3.32.3 | 5 / 11 | |
| 3.32.2 | 5 / 11 | |
| 3.32.0 | 5 / 11 | |
| 3.31.9 | 5 / 11 | |
| 3.31.7 | 5 / 11 |
v3.40.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.39.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.39.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.39.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.39.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.39.28
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-07-08. This could indicate a legitimate maintainer transition or an account compromise.
v3.38.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.33.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.33.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.33.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.32.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.32.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.32.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.32.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.31.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.31.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.