@bufbuild/cel
A CEL evaluator for ECMAScript
7
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
bufdevtstamm-bufbufbotjdailey_bufdoriakeung
Keywords
javascripttypescriptprotobufcelcommon-expression-language
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:peggy-ts | AI (npm-metadata): Dev-only dependency used for parser generation; does not affect runtime consumers. | ai | |
| source-diff | net-exec-file:dist/cjs/eval.js | AI (source-diff): Compiled CEL evaluator code with Apache-2.0 header; no actual network calls or malicious exec. | ai | |
| source-diff | net-exec-file:dist/esm/eval.js | AI (source-diff): ESM variant of same clean CEL evaluator code; false positive. | ai | |
| source-diff | net-exec-file:dist/esm/plan.js | AI (source-diff): ESM variant of same clean CEL planner code; false positive. | ai | |
| source-diff | net-exec-file:dist/cjs/plan.js | AI (source-diff): Compiled CEL planner code; imports are all @bufbuild/* packages, no malicious behavior. | ai | |
| provenance | publisher-changed | AI (provenance): Both publishers are buf.build org accounts; internal maintainer rotation within the same org. | ai | |
| provenance | no-provenance | AI (provenance): Bufbuild org package; lack of Sigstore attestation is common and not a risk signal here. | ai |