@lynx-js/rspeedy-canary
A webpack/rspack-based frontend toolchain for Lynx
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src_config_validate_ts.js | AI (source-diff): Bundled webpack chunk (typia dep), not obfuscation; expected for rslib build output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Result of bundling deps into dist during build tooling change. | ai | |
| provenance | publisher-changed | AI (provenance): CI automation publisher with intact SLSA provenance; monorepo canary release pattern. | ai | |
| source-diff | obfuscated-file:dist/0~src_config_validate_ts.js | AI (source-diff): Webpack-bundled typia validation code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/1~src_config_validate_ts.js | AI (source-diff): Webpack-bundled typia validation code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/0~validate.js | AI (source-diff): Standard rspack/webpack bundle output; long lines from minification, not obfuscation. Consistent with this build toolchain package. | ai | |
| source-diff | obfuscated-file:dist/1~validate.js | AI (source-diff): Same as dist/0~validate.js — rspack bundle artifact, not malicious obfuscation. | ai | |
| dependencies | unvetted-dep:@lynx-js/cache-events-webpack-plugin | AI (dependencies): Canary alias within the same @lynx-js org; consistent with this package's release pattern. | ai | |
| dependencies | unvetted-dep:@rsdoctor/rspack-plugin | AI (dependencies): Well-known rsdoctor tooling from the rsbuild/rspack ecosystem; stable dependency. | ai | |
| dependencies | unvetted-dep:@lynx-js/chunk-loading-webpack-plugin | AI (dependencies): Canary alias of a first-party @lynx-js package; consistent with this package's canary release pattern. | ai |
Versions (showing 51 of 53)
| Version | Deps | Published |
|---|---|---|
| 0.16.1 | 9 / 20 | |
| 0.16.0 | 9 / 20 | |
| 0.15.2 | 9 / 20 | |
| 0.15.1 | 9 / 20 | |
| 0.15.0 | 9 / 20 | |
| 0.14.5 | 8 / 20 | |
| 0.14.4 | 8 / 20 | |
| 0.14.3 | 8 / 20 | |
| 0.14.2 | 8 / 19 | |
| 0.14.1 | 8 / 19 | |
| 0.14.0 | 8 / 19 | |
| 0.13.6 | 8 / 19 | |
| 0.13.5 | 8 / 19 | |
| 0.13.4 | 8 / 19 | |
| 0.13.3 | 8 / 19 | |
| 0.13.2 | 8 / 19 | |
| 0.13.1 | 8 / 19 | |
| 0.13.0 | 8 / 19 | |
| 0.12.5 | 8 / 19 | |
| 0.12.4 | 8 / 19 | |
| 0.12.3 | 8 / 19 | |
| 0.12.2 | 8 / 19 | |
| 0.12.1 | 8 / 19 | |
| 0.12.0 | 8 / 19 | |
| 0.11.9 | 8 / 19 | |
| 0.11.8 | 8 / 19 | |
| 0.11.2 | 7 / 19 | |
| 0.11.1 | 7 / 19 | |
| 0.11.0 | 7 / 19 | |
| 0.10.8 | 7 / 18 | |
| 0.10.7 | 6 / 18 | |
| 0.10.6 | 6 / 18 | |
| 0.10.5 | 6 / 20 | |
| 0.10.4 | 6 / 20 | |
| 0.10.3 | 6 / 20 | |
| 0.10.2 | 6 / 20 | |
| 0.10.1 | 6 / 20 | |
| 0.10.0 | 6 / 20 | |
| 0.9.11 | 6 / 20 | |
| 0.9.10 | 6 / 20 | |
| 0.9.9 | 6 / 20 | |
| 0.9.8 | 6 / 20 | |
| 0.9.7 | 6 / 20 | |
| 0.9.6 | 6 / 20 | |
| 0.9.5 | 6 / 20 | |
| 0.9.4 | 6 / 20 | |
| 0.9.3 | 6 / 20 | |
| 0.8.7 | 16 / 7 | |
| 0.8.6 | 16 / 7 | |
| 0.8.5 | 16 / 7 | |
| 0.8.4 | 16 / 7 |
v0.16.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.6
4 findingsThis version was published by a different npm account than previous versions on 2026-03-24. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.5
4 findingsThis version was published by a different npm account than previous versions on 2026-03-09. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.4
4 findingsThis version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.3
4 findingsThis version was published by a different npm account than previous versions on 2026-02-01. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.2
4 findingsThis version was published by a different npm account than previous versions on 2026-01-26. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.1
4 findingsThis version was published by a different npm account than previous versions on 2026-01-25. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.0
4 findingsThis version was published by a different npm account than previous versions on 2026-01-11. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.5
4 findingsThis version was published by a different npm account than previous versions on 2026-01-04. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.4
4 findingsThis version was published by a different npm account than previous versions on 2025-12-29. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.3
4 findingsThis version was published by a different npm account than previous versions on 2025-12-22. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.2
4 findingsThis version was published by a different npm account than previous versions on 2025-12-14. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.1
4 findingsThis version was published by a different npm account than previous versions on 2025-12-07. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.0
4 findingsThis version was published by a different npm account than previous versions on 2025-11-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.9
4 findingsThis version was published by a different npm account than previous versions on 2025-11-10. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.8
4 findingsThis version was published by a different npm account than previous versions on 2025-11-03. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.