← Home

@marko/compiler

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

ryansolidmlrawlingsagligaryanturnquisttigtdylanpierceylulavalva

Keywords

babelhtmljsmarkoparseparserplugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:jsesc AI (phantom-deps): Config-file reference in established compiler; stable pattern. ai
phantom-deps phantom-dep:resolve-from AI (phantom-deps): Config-file reference in established compiler; stable pattern. ai
phantom-deps phantom-dep:strip-ansi AI (phantom-deps): Config-file reference in established compiler; stable pattern. ai
phantom-deps phantom-dep:@babel/generator AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. ai
phantom-deps phantom-dep:@babel/parser AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. ai
phantom-deps phantom-dep:@babel/types AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. ai
publish-pattern new-deps-added AI (publish-pattern): magic-string is a well-known, widely used string-manipulation dep for compilers. ai
provenance missing-githead AI (provenance): CI metadata gap, offset by SLSA attestation and unchanged provenance direction. ai
source-diff net-exec-file:dist/babel.web.js AI (source-diff): False positive — bundled Babel code triggers net+exec heuristic. No actual malicious network or execution patterns in the sample. ai
source-diff obfuscated-file:dist/babel.web.js AI (source-diff): dist/babel.web.js is a bundled browser-targeted build artifact. Long lines are from bundling, not obfuscation. Expected for a compiler package. ai
source-diff net-exec-file:dist/babel.js AI (source-diff): False positive: Babel's code generation uses Function constructors internally; no actual malicious network+exec pattern. This is bundled Babel source code. ai
source-diff obfuscated-file:dist/babel.js AI (source-diff): dist/babel.js is an esbuild bundle of @babel/* deps (which were removed from runtime deps). Long lines are standard bundler output, not obfuscation. Stable architectural pattern for this package. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling all @babel/* runtime deps into dist/babel.js, which were simultaneously removed from package dependencies. Expected architectural change. ai
provenance publisher-changed AI (provenance): Publisher changed from dylanpiercey to GitHub Actions CI/CD — a legitimate and recommended security improvement for the marko-js/marko monorepo, backed by SLSA provenance attestation. ai
publish-pattern dormant-publish AI (publish-pattern): Apparent dormancy is an artifact of the publisher account change (personal → GitHub Actions). Package has 368 versions and active ecosystem use; not a genuine dormancy signal. ai
phantom-deps phantom-dep:@babel/plugin-syntax-typescript AI (phantom-deps): Framework-scoped Babel plugin loaded by convention in the Marko compiler; not a direct import but a legitimate peer/convention dependency. ai
dependencies unvetted-dep:htmljs-parser AI (dependencies): htmljs-parser is a core Marko ecosystem parser maintained by the same marko-js org; stable legitimate dependency. ai
phantom-deps phantom-dep:self-closing-tags AI (phantom-deps): self-closing-tags is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. ai
phantom-deps phantom-dep:complain AI (phantom-deps): complain is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. ai
phantom-deps phantom-dep:he AI (phantom-deps): he is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. ai
dependencies unvetted-dep:@luxass/strip-json-comments AI (dependencies): Strip-json-comments utility; no security concerns for this compiler package context. ai
dependencies unvetted-dep:complain AI (dependencies): complain is a well-known deprecation warning utility with a long history; no security concerns. ai
dependencies unvetted-dep:relative-import-path AI (dependencies): relative-import-path is a small Marko ecosystem utility; stable legitimate dependency. ai
dependencies unvetted-dep:self-closing-tags AI (dependencies): self-closing-tags is a small Marko ecosystem utility; stable legitimate dependency. ai
dependencies unvetted-dep:lasso-package-root AI (dependencies): lasso-package-root is part of the eBay Lasso/Marko ecosystem; stable legitimate dependency. ai
dependencies unvetted-dep:raptor-regexp AI (dependencies): raptor-regexp is a long-standing eBay/Marko ecosystem utility package; stable legitimate dependency. ai
dependencies unvetted-dep:raptor-util AI (dependencies): raptor-util is a long-standing eBay/Marko ecosystem utility package; stable legitimate dependency. ai

Versions (showing 51 of 293)

View all versions
Version Deps Published
5.41.9 14 / 1
5.41.8 14 / 1
5.41.7 14 / 1
5.41.6 14 / 1
5.41.5 14 / 1
5.41.4 14 / 1
5.41.3 13 / 1
5.41.2 13 / 1
5.41.1 13 / 1
5.41.0 13 / 1
5.40.2 13 / 1
5.40.1 13 / 1
5.40.0 13 / 1
5.39.66 13 / 1
5.39.65 13 / 1
5.39.64 13 / 1
5.39.63 13 / 1
5.39.62 13 / 1
5.39.61 13 / 1
5.39.60 13 / 1
5.39.59 13 / 1
5.39.58 13 / 1
5.39.57 13 / 1
5.39.56 13 / 1
5.39.55 13 / 1
5.39.54 13 / 1
5.39.53 13 / 1
5.39.52 13 / 1
5.39.51 13 / 1
5.39.50 23 / 1
5.39.49 23 / 1
5.39.48 23 / 1
5.39.47 23 / 1
5.39.46 23 / 1
5.39.45 23 / 1
5.39.44 23 / 1
5.39.43 23 / 1
5.39.42 23 / 1
5.39.41 23 / 1
5.39.40 23 / 1
5.39.39 23 / 1
5.39.38 23 / 1
5.39.37 23 / 1
5.39.36 23 / 1
5.39.35 23 / 1
5.39.34 23 / 1
5.39.33 23 / 1
5.39.32 23 / 1
5.39.31 23 / 1
5.39.30 23 / 1
5.39.29 23 / 1

v5.41.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.41.8

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v5.41.7

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v5.41.6

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v5.41.5

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v5.41.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.41.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.41.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.41.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.40.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.40.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.