@bunchtogether/hash-object
[Hash Object](https://github.com/bunchtogether/hash-object) [](https://circleci.com/gh/bunchtogether/hash-object/tree/master) [ relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:farmhash.wasm | AI (dependencies): farmhash.wasm is the WebAssembly fallback for browser environments, consistent with the package's browser field in package.json. Legitimate use for cross-environment hashing support. | ai | |
| dependencies | unvetted-dep:farmhash | AI (dependencies): farmhash is a well-known Google FarmHash native binding, widely used in the Node.js ecosystem. Its use in a hashing utility is entirely expected and legitimate. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is common (~88% of packages); publisher has a clean track record with 17 approved packages. Not a meaningful risk signal for this package. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 1.0.7 | 1 / 33 | |
| 1.0.6 | 1 / 33 | |
| 1.0.5 | 1 / 33 | |
| 1.0.4 | 1 / 26 | |
| 1.0.3 | 1 / 25 | |
| 1.0.2 | 1 / 25 | |
| 1.0.0 | 3 / 25 |
v1.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.