← Home

@esbuild/android-arm

A WebAssembly shim for esbuild on Android ARM.

51
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

esbuild

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): esbuild.wasm is the package's core artifact; expected for a wasm platform shim. ai
dependencies unvetted-dep:esbuild-wasm AI (dependencies): esbuild-wasm is the official WebAssembly build of esbuild by the same author; its use as a dependency in @esbuild/android-arm is expected and stable across versions. ai
phantom-deps phantom-dep:esbuild-wasm AI (phantom-deps): esbuild-wasm is a platform-specific dependency correctly declared but not directly imported; this is the intended design for platform shims. ai
provenance publisher-changed AI (provenance): esbuild migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation; this is a legitimate and security-improving transition, not a takeover. ai
maintainer-change maintainer-removed AI (maintainer-change): evanw's removal as direct npm publisher reflects the move to automated GitHub Actions publishing with SLSA attestation, not a package takeover. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() usage is in wasm_exec.js, the standard Go WebAssembly runtime shim — expected and benign for this package. ai
bogus-package bogus-package AI (bogus-package): Platform-specific binary shim; minimal README, no keywords, and tiny payload are expected and appropriate for this package type. ai

Versions (showing 51 of 123)

View all versions
Version Deps Published
0.28.1 0 / 0
0.28.0 0 / 0
0.27.7 0 / 0
0.27.6 0 / 0
0.27.5 0 / 0
0.27.4 0 / 0
0.27.3 0 / 0
0.27.2 0 / 0
0.27.1 0 / 0
0.27.0 0 / 0
0.26.0 0 / 0
0.25.12 0 / 0
0.25.11 0 / 0
0.25.10 0 / 0
0.25.9 0 / 0
0.25.8 0 / 0
0.25.7 0 / 0
0.25.6 0 / 0
0.25.5 0 / 0
0.25.4 0 / 0
0.25.3 0 / 0
0.25.2 0 / 0
0.25.1 0 / 0
0.25.0 0 / 0
0.24.2 0 / 0
0.24.1 0 / 0
0.24.0 0 / 0
0.23.1 0 / 0
0.23.0 0 / 0
0.22.0 0 / 0
0.21.5 0 / 0
0.21.4 0 / 0
0.21.3 0 / 0
0.21.2 0 / 0
0.21.1 0 / 0
0.21.0 0 / 0
0.20.2 0 / 0
0.20.1 0 / 0
0.20.0 0 / 0
0.19.12 0 / 0
0.19.11 0 / 0
0.19.10 0 / 0
0.19.9 0 / 0
0.19.8 0 / 0
0.19.7 0 / 0
0.19.6 0 / 0
0.19.5 0 / 0
0.19.4 0 / 0
0.19.3 0 / 0
0.19.2 0 / 0
0.19.1 0 / 0

v0.28.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • esbuild.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.