@genesislcap/build-kit
Build utilities & types
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): High-frequency automated publishing is the norm for this package (1898 versions); rapid-publish is a stable false positive here. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): handlebars is a well-known templating library; stable dependency for this build-kit package across versions. | ai | |
| provenance | no-provenance | AI (provenance): Genesis ecosystem packages consistently lack provenance; stable false positive for this publisher. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 14.449.0 | 18 / 5 | |
| 14.444.0 | 18 / 5 | |
| 14.439.3 | 18 / 5 | |
| 14.439.2 | 18 / 5 | |
| 14.439.1 | 18 / 5 | |
| 14.439.0 | 18 / 5 | |
| 14.438.1 | 18 / 5 | |
| 14.438.0 | 18 / 5 | |
| 14.437.6 | 18 / 5 | |
| 14.428.1 | 18 / 5 | |
| 14.428.0 | 18 / 5 | |
| 14.416.0 | 18 / 5 | |
| 14.409.1 | 18 / 5 | |
| 14.401.2 | 18 / 5 | |
| 14.401.0 | 18 / 5 | |
| 14.400.0 | 18 / 5 | |
| 14.399.0 | 18 / 5 | |
| 14.354.5 | 18 / 5 |
v14.449.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.444.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.438.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.438.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.437.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.428.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.428.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.416.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.409.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.401.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.401.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.400.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.399.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.354.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.