@bytecodealliance/jco-transpile
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:vendor/js-component-bindgen-component.js | AI (source-diff): Base64-embedded wasm modules in generated vendor bindings, not payload obfuscation. | ai | |
| source-diff | encoded-string-file:vendor/wasm-tools.js | AI (source-diff): Same base64-wasm pattern in vendor bindgen output. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Vendor wasm-tools/bindgen compiled artifacts are the package's stated function. | ai | |
| phantom-deps | phantom-dep:binaryen | AI (phantom-deps): Used via build tooling/config, not direct import. | ai | |
| phantom-deps | phantom-dep:@bytecodealliance/preview3-shim | AI (phantom-deps): Same-org sibling dependency, expected pattern. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 0.5.2 | 4 / 9 | |
| 0.5.1 | 4 / 9 | |
| 0.5.0 | 4 / 9 | |
| 0.4.2 | 4 / 10 | |
| 0.4.1 | 4 / 10 | |
| 0.3.9 | 3 / 4 | |
| 0.3.8 | 3 / 4 | |
| 0.3.7 | 3 / 4 | |
| 0.3.6 | 3 / 4 | |
| 0.3.5 | 3 / 4 | |
| 0.3.4 | 3 / 4 | |
| 0.3.3 | 3 / 4 | |
| 0.3.2 | 3 / 4 | |
| 0.3.1 | 3 / 4 | |
| 0.3.0 | 3 / 4 | |
| 0.2.0 | 2 / 4 | |
| 0.1.3 | 2 / 4 | |
| 0.1.2 | 2 / 4 |
v0.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
4 findingsPackage contains compiled binaries that could be backdoors: • vendor/js-component-bindgen-component.core.wasm • vendor/js-component-bindgen-component.core2.wasm • vendor/wasm-tools.core.wasm • vendor/wasm-tools.core2.wasm
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.9
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.8
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.7
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.