@marko/compiler
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:jsesc | AI (phantom-deps): Config-file reference in established compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:resolve-from | AI (phantom-deps): Config-file reference in established compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:strip-ansi | AI (phantom-deps): Config-file reference in established compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/generator | AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/types | AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): magic-string is a well-known, widely used string-manipulation dep for compilers. | ai | |
| provenance | missing-githead | AI (provenance): CI metadata gap, offset by SLSA attestation and unchanged provenance direction. | ai | |
| source-diff | net-exec-file:dist/babel.web.js | AI (source-diff): False positive — bundled Babel code triggers net+exec heuristic. No actual malicious network or execution patterns in the sample. | ai | |
| source-diff | obfuscated-file:dist/babel.web.js | AI (source-diff): dist/babel.web.js is a bundled browser-targeted build artifact. Long lines are from bundling, not obfuscation. Expected for a compiler package. | ai | |
| source-diff | net-exec-file:dist/babel.js | AI (source-diff): False positive: Babel's code generation uses Function constructors internally; no actual malicious network+exec pattern. This is bundled Babel source code. | ai | |
| source-diff | obfuscated-file:dist/babel.js | AI (source-diff): dist/babel.js is an esbuild bundle of @babel/* deps (which were removed from runtime deps). Long lines are standard bundler output, not obfuscation. Stable architectural pattern for this package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by bundling all @babel/* runtime deps into dist/babel.js, which were simultaneously removed from package dependencies. Expected architectural change. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from dylanpiercey to GitHub Actions CI/CD — a legitimate and recommended security improvement for the marko-js/marko monorepo, backed by SLSA provenance attestation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Apparent dormancy is an artifact of the publisher account change (personal → GitHub Actions). Package has 368 versions and active ecosystem use; not a genuine dormancy signal. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-typescript | AI (phantom-deps): Framework-scoped Babel plugin loaded by convention in the Marko compiler; not a direct import but a legitimate peer/convention dependency. | ai | |
| dependencies | unvetted-dep:htmljs-parser | AI (dependencies): htmljs-parser is a core Marko ecosystem parser maintained by the same marko-js org; stable legitimate dependency. | ai | |
| phantom-deps | phantom-dep:self-closing-tags | AI (phantom-deps): self-closing-tags is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. | ai | |
| phantom-deps | phantom-dep:complain | AI (phantom-deps): complain is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. | ai | |
| phantom-deps | phantom-dep:he | AI (phantom-deps): he is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. | ai | |
| dependencies | unvetted-dep:@luxass/strip-json-comments | AI (dependencies): Strip-json-comments utility; no security concerns for this compiler package context. | ai | |
| dependencies | unvetted-dep:complain | AI (dependencies): complain is a well-known deprecation warning utility with a long history; no security concerns. | ai | |
| dependencies | unvetted-dep:relative-import-path | AI (dependencies): relative-import-path is a small Marko ecosystem utility; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:self-closing-tags | AI (dependencies): self-closing-tags is a small Marko ecosystem utility; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:lasso-package-root | AI (dependencies): lasso-package-root is part of the eBay Lasso/Marko ecosystem; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:raptor-regexp | AI (dependencies): raptor-regexp is a long-standing eBay/Marko ecosystem utility package; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:raptor-util | AI (dependencies): raptor-util is a long-standing eBay/Marko ecosystem utility package; stable legitimate dependency. | ai |
Versions (showing 51 of 293)
| Version | Deps | Published |
|---|---|---|
| 5.41.9 | 14 / 1 | |
| 5.41.8 | 14 / 1 | |
| 5.41.7 | 14 / 1 | |
| 5.41.6 | 14 / 1 | |
| 5.41.5 | 14 / 1 | |
| 5.41.4 | 14 / 1 | |
| 5.41.3 | 13 / 1 | |
| 5.41.2 | 13 / 1 | |
| 5.41.1 | 13 / 1 | |
| 5.41.0 | 13 / 1 | |
| 5.40.2 | 13 / 1 | |
| 5.40.1 | 13 / 1 | |
| 5.40.0 | 13 / 1 | |
| 5.39.66 | 13 / 1 | |
| 5.39.65 | 13 / 1 | |
| 5.39.64 | 13 / 1 | |
| 5.39.63 | 13 / 1 | |
| 5.39.62 | 13 / 1 | |
| 5.39.61 | 13 / 1 | |
| 5.39.60 | 13 / 1 | |
| 5.39.59 | 13 / 1 | |
| 5.39.58 | 13 / 1 | |
| 5.39.57 | 13 / 1 | |
| 5.39.56 | 13 / 1 | |
| 5.39.55 | 13 / 1 | |
| 5.39.54 | 13 / 1 | |
| 5.39.53 | 13 / 1 | |
| 5.39.52 | 13 / 1 | |
| 5.39.51 | 13 / 1 | |
| 5.39.50 | 23 / 1 | |
| 5.39.49 | 23 / 1 | |
| 5.39.48 | 23 / 1 | |
| 5.39.47 | 23 / 1 | |
| 5.39.46 | 23 / 1 | |
| 5.39.45 | 23 / 1 | |
| 5.39.44 | 23 / 1 | |
| 5.39.43 | 23 / 1 | |
| 5.39.42 | 23 / 1 | |
| 5.39.41 | 23 / 1 | |
| 5.39.40 | 23 / 1 | |
| 5.39.39 | 23 / 1 | |
| 5.39.38 | 23 / 1 | |
| 5.39.37 | 23 / 1 | |
| 5.39.36 | 23 / 1 | |
| 5.39.35 | 23 / 1 | |
| 5.39.34 | 23 / 1 | |
| 5.39.33 | 23 / 1 | |
| 5.39.32 | 23 / 1 | |
| 5.39.31 | 23 / 1 | |
| 5.39.30 | 23 / 1 | |
| 5.39.29 | 23 / 1 |
v5.41.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.8
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.7
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.6
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.5
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.40.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.40.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.