← Home

@cocos/ccbuild

The next generation of build tool for Cocos engine.

3
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

devhacker520cocos-creator

Keywords

cocosenginebuildcompile

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/babel__traverse AI (phantom-deps): Framework-scoped type declarations loaded by convention in build tool. ai
phantom-deps phantom-dep:@types/babel__template AI (phantom-deps): Framework-scoped type declarations loaded by convention in build tool. ai
phantom-deps phantom-dep:@types/babel__core AI (phantom-deps): Framework-scoped type declarations loaded by convention in build tool. ai
phantom-deps phantom-dep:@types/babel__helper-module-imports AI (phantom-deps): Framework-scoped type declarations loaded by convention in build tool. ai
phantom-deps phantom-dep:@types/babel__preset-env AI (phantom-deps): Framework-scoped type declarations loaded by convention in build tool. ai
phantom-deps phantom-dep:@types/babel__generator AI (phantom-deps): Framework-scoped type declarations loaded by convention in build tool. ai
phantom-deps phantom-dep:@types/resolve AI (phantom-deps): Framework-scoped type declarations loaded by convention in build tool. ai
dependencies unvetted-dep:@types/babel__helper-module-imports AI (dependencies): Type-only dev dependency; no runtime risk. ai
dependencies unvetted-dep:@cocos/tfig AI (dependencies): First-party @cocos scoped dep from the same publisher; stable for this package. ai
dependencies unvetted-dep:@cocos/creator-programming-babel-preset-cc AI (dependencies): First-party @cocos scoped babel preset; stable for this package. ai
dependencies unvetted-dep:@cocos/typescript AI (dependencies): First-party @cocos scoped TypeScript fork; stable for this package. ai
dependencies unvetted-dep:@cocos/rollup-plugin-terser AI (dependencies): First-party @cocos scoped rollup plugin; stable for this package. ai
dependencies unvetted-dep:@cocos/rollup-plugin-typescript AI (dependencies): First-party @cocos scoped rollup plugin; stable for this package. ai
dependencies unvetted-dep:@cocos/rollup-plugin-node-resolve AI (dependencies): First-party @cocos scoped rollup plugin; stable for this package. ai
dependencies unvetted-dep:@cocos/babel-plugin-dynamic-import-vars AI (dependencies): First-party @cocos scoped babel plugin; stable for this package. ai
dependencies unvetted-dep:@types/babel__preset-env AI (dependencies): Type-only dev dependency; no runtime risk. ai
typosquat typosquat.levenshtein:esbuild AI (typosquat): @cocos/ccbuild is a Cocos Engine build tool; not a plausible typosquat of esbuild. ai
phantom-deps phantom-dep:commander AI (phantom-deps): commander is declared as a dependency; phantom-dep heuristic false positive for this CLI build tool. ai
phantom-deps phantom-dep:resolve AI (phantom-deps): resolve is declared as a dependency; phantom-dep heuristic false positive for this build tool. ai
phantom-deps phantom-dep:ejs AI (phantom-deps): ejs is declared as a dependency and used by the build tool; phantom-dep heuristic false positive. ai
semgrep semgrep:dynamic-require AI (semgrep): Module resolution pattern in a build tool; resolvedPath is derived from engine module lookup, not external input. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used in enum expression evaluator within a build tool; input is source code, not user data. ai

Versions (showing 3 of 3)

Version Deps Published
2.3.19 45 / 0
2.3.18 45 / 0
2.3.17 46 / 0

v2.3.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.