← Home

@bytecodealliance/jco

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tschneidereitcfallinguybedfordvados

Keywords

ComponentWasmWebAssembly

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@bytecodealliance/componentize-js-0-19-3 AI (dependencies): Aliased pin of first-party componentize-js for fallback path. ai
npm-metadata bundled-binaries AI (npm-metadata): WASI preview1 adapter wasm is core to jco's function; stable across versions. ai
phantom-deps phantom-dep:terser AI (phantom-deps): terser is a declared dep used via config/build tooling; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:@bytecodealliance/preview3-shim AI (phantom-deps): Same org scope; declared as runtime dep, likely used indirectly or conditionally. ai
provenance missing-githead AI (provenance): SLSA provenance present; gitHead absence reflects CI change, not a supply-chain concern for this package. ai
provenance publisher-changed AI (provenance): Bytecode Alliance transitioned to GitHub Actions CI/CD publishing with SLSA provenance attestation. This is a legitimate and security-improving change, not a compromise. ai
license uncommon-license:LLVM-exception AI (license): Apache-2.0 WITH LLVM-exception is a well-known permissive license used throughout the LLVM/Rust ecosystem; no legal concern for this package. ai
source-diff encoded-string-file:obj/wasm-tools.js AI (source-diff): Base64 strings are inline WASM module binaries loaded via WebAssembly.compile(). Standard pattern for jco's wasm-tools JS bindings; not malicious obfuscation. ai
source-diff encoded-string-file:obj/js-component-bindgen-component.js AI (source-diff): Base64 strings are inline WASM module binaries loaded via WebAssembly.compile(). Standard pattern for jco's WASM component bindgen tooling; not malicious obfuscation. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @bytecodealliance/jco is a scoped package from the Bytecode Alliance for WebAssembly tooling; levenshtein match to 'joi' is a false positive with no plausible confusion. ai
phantom-deps phantom-dep:binaryen AI (phantom-deps): binaryen is a declared runtime dependency used for WASM optimization; phantom detection is a false positive for this package's usage pattern. ai
phantom-deps phantom-dep:mkdirp AI (phantom-deps): mkdirp is a declared runtime dependency used in build/CLI tooling; phantom detection is a false positive for this package's usage pattern. ai
phantom-deps phantom-dep:ora AI (phantom-deps): ora is conditionally loaded via the #ora import map (browser shim vs native); phantom-dep detection doesn't account for import map indirection. ai
semgrep semgrep:eval-usage AI (semgrep): eval('import(...)') is a known ESM dynamic import workaround used to conditionally load one of two compatible versions of componentize-js; not an attack vector. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode is used to load embedded WASM modules via WebAssembly.compile() — standard and documented pattern for WASM-in-JS bundles. ai

Versions (showing 51 of 73)

View all versions
Version Deps Published
1.25.1 9 / 13
1.25.0 9 / 13
1.24.6 10 / 13
1.24.5 10 / 13
1.24.4 10 / 13
1.24.3 10 / 13
1.24.2 10 / 13
1.24.1 9 / 13
1.24.0 9 / 13
1.23.1 9 / 13
1.23.0 9 / 13
1.22.0 9 / 13
1.21.0 9 / 13
1.20.0 9 / 13
1.19.0 8 / 13
1.18.1 8 / 13
1.18.0 8 / 13
1.17.9 7 / 13
1.17.8 7 / 13
1.17.7 7 / 13
1.17.6 7 / 13
1.17.5 7 / 13
1.17.4 7 / 13
1.17.3 7 / 13
1.17.2 7 / 13
1.17.1 7 / 13
1.17.0 7 / 13
1.16.1 7 / 15
1.16.0 7 / 15
1.15.4 7 / 15
1.15.3 7 / 14
1.15.2 7 / 14
1.15.1 7 / 13
1.15.0 7 / 13
1.14.0 8 / 16
1.13.3 8 / 16
1.13.2 8 / 16
1.13.1 8 / 16
1.13.0 8 / 16
1.12.0 8 / 16
1.11.3 8 / 16
1.11.2 8 / 16
1.11.1 8 / 12
1.11.0 8 / 12
1.10.2 8 / 8
1.10.1 8 / 8
1.10.0 8 / 8
1.9.1 8 / 8
1.8.1 8 / 8
1.8.0 8 / 8
1.7.2 8 / 8

v1.25.1

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/wasi_snapshot_preview1.command.wasm • lib/wasi_snapshot_preview1.reactor.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.25.0

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • lib/wasi_snapshot_preview1.command.wasm • lib/wasi_snapshot_preview1.reactor.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.24.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.24.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.