@hyperse/hps-plugin-build
A production build plugin for the HPS (Hyperse) build system that provides optimized builds using Rspack with configurable compression, module filtering, and build timing for web applications.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@hyperse/config-loader | AI (dependencies): Same org scope (@hyperse); consistent with the package's own namespace, low risk. | ai | |
| phantom-deps | phantom-dep:@hyperse/config-loader | AI (phantom-deps): Same-org scoped dep; likely re-exported or used indirectly via barrel imports — stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Consistent across all 28 versions; no provenance is the norm for this org. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 1.0.1 | 3 / 11 | |
| 1.0.0 | 3 / 11 | |
| 0.1.6 | 3 / 11 | |
| 0.1.5 | 3 / 12 | |
| 0.1.4 | 3 / 12 | |
| 0.1.3 | 3 / 12 | |
| 0.1.2 | 3 / 11 | |
| 0.1.1 | 3 / 11 | |
| 0.1.0 | 3 / 11 |
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.