@esbuild/openharmony-arm64
A WebAssembly shim for esbuild on OpenHarmony ARM64.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): esbuild.wasm is the package's core artifact; expected for wasm shim. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD with SLSA attestation; provenance improved. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() in wasm_exec.js is standard Go WASM runtime boilerplate; stable false positive for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): New platform target (OpenHarmony) added after gap; SLSA provenance confirms legitimate CI/CD publish. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Platform-specific shim stub; tiny payload and no deps are by design for esbuild's OS/CPU-targeted packages. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.28.1 | 0 / 0 | |
| 0.28.0 | 0 / 0 | |
| 0.27.7 | 0 / 0 | |
| 0.27.6 | 0 / 0 | |
| 0.27.5 | 0 / 0 | |
| 0.27.4 | 0 / 0 | |
| 0.27.3 | 0 / 0 | |
| 0.27.2 | 0 / 0 | |
| 0.27.1 | 0 / 0 | |
| 0.0.1 | 0 / 0 |
v0.27.7
3 findingsPackage contains compiled binaries that could be backdoors: • esbuild.wasm
This version was published by a different npm account than previous versions on 2026-04-02. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.5
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (esbuild) on 2026-04-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.27.4
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (esbuild) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.27.3
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (esbuild) on 2026-02-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.27.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (esbuild) on 2025-12-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.27.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (esbuild) on 2025-12-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.