@marko/compiler
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:jsesc | AI (phantom-deps): Config-file reference in established compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:resolve-from | AI (phantom-deps): Config-file reference in established compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:strip-ansi | AI (phantom-deps): Config-file reference in established compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/generator | AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/types | AI (phantom-deps): Framework-scoped Babel package loaded by convention in compiler; stable pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): magic-string is a well-known, widely used string-manipulation dep for compilers. | ai | |
| provenance | missing-githead | AI (provenance): CI metadata gap, offset by SLSA attestation and unchanged provenance direction. | ai | |
| source-diff | net-exec-file:dist/babel.web.js | AI (source-diff): False positive — bundled Babel code triggers net+exec heuristic. No actual malicious network or execution patterns in the sample. | ai | |
| source-diff | obfuscated-file:dist/babel.web.js | AI (source-diff): dist/babel.web.js is a bundled browser-targeted build artifact. Long lines are from bundling, not obfuscation. Expected for a compiler package. | ai | |
| source-diff | net-exec-file:dist/babel.js | AI (source-diff): False positive: Babel's code generation uses Function constructors internally; no actual malicious network+exec pattern. This is bundled Babel source code. | ai | |
| source-diff | obfuscated-file:dist/babel.js | AI (source-diff): dist/babel.js is an esbuild bundle of @babel/* deps (which were removed from runtime deps). Long lines are standard bundler output, not obfuscation. Stable architectural pattern for this package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by bundling all @babel/* runtime deps into dist/babel.js, which were simultaneously removed from package dependencies. Expected architectural change. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from dylanpiercey to GitHub Actions CI/CD — a legitimate and recommended security improvement for the marko-js/marko monorepo, backed by SLSA provenance attestation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Apparent dormancy is an artifact of the publisher account change (personal → GitHub Actions). Package has 368 versions and active ecosystem use; not a genuine dormancy signal. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-typescript | AI (phantom-deps): Framework-scoped Babel plugin loaded by convention in the Marko compiler; not a direct import but a legitimate peer/convention dependency. | ai | |
| dependencies | unvetted-dep:htmljs-parser | AI (dependencies): htmljs-parser is a core Marko ecosystem parser maintained by the same marko-js org; stable legitimate dependency. | ai | |
| phantom-deps | phantom-dep:self-closing-tags | AI (phantom-deps): self-closing-tags is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. | ai | |
| phantom-deps | phantom-dep:complain | AI (phantom-deps): complain is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. | ai | |
| phantom-deps | phantom-dep:he | AI (phantom-deps): he is a declared runtime dependency; phantom detection reflects config-file-only reference, not a security issue. | ai | |
| dependencies | unvetted-dep:@luxass/strip-json-comments | AI (dependencies): Strip-json-comments utility; no security concerns for this compiler package context. | ai | |
| dependencies | unvetted-dep:complain | AI (dependencies): complain is a well-known deprecation warning utility with a long history; no security concerns. | ai | |
| dependencies | unvetted-dep:relative-import-path | AI (dependencies): relative-import-path is a small Marko ecosystem utility; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:self-closing-tags | AI (dependencies): self-closing-tags is a small Marko ecosystem utility; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:lasso-package-root | AI (dependencies): lasso-package-root is part of the eBay Lasso/Marko ecosystem; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:raptor-regexp | AI (dependencies): raptor-regexp is a long-standing eBay/Marko ecosystem utility package; stable legitimate dependency. | ai | |
| dependencies | unvetted-dep:raptor-util | AI (dependencies): raptor-util is a long-standing eBay/Marko ecosystem utility package; stable legitimate dependency. | ai |
Versions (showing 100 of 293)
| Version | Deps | Published |
|---|---|---|
| 5.41.9 | 14 / 1 | |
| 5.41.8 | 14 / 1 | |
| 5.41.7 | 14 / 1 | |
| 5.41.6 | 14 / 1 | |
| 5.41.5 | 14 / 1 | |
| 5.41.4 | 14 / 1 | |
| 5.41.3 | 13 / 1 | |
| 5.41.2 | 13 / 1 | |
| 5.41.1 | 13 / 1 | |
| 5.41.0 | 13 / 1 | |
| 5.40.2 | 13 / 1 | |
| 5.40.1 | 13 / 1 | |
| 5.40.0 | 13 / 1 | |
| 5.39.66 | 13 / 1 | |
| 5.39.65 | 13 / 1 | |
| 5.39.64 | 13 / 1 | |
| 5.39.63 | 13 / 1 | |
| 5.39.62 | 13 / 1 | |
| 5.39.61 | 13 / 1 | |
| 5.39.60 | 13 / 1 | |
| 5.39.59 | 13 / 1 | |
| 5.39.58 | 13 / 1 | |
| 5.39.57 | 13 / 1 | |
| 5.39.56 | 13 / 1 | |
| 5.39.55 | 13 / 1 | |
| 5.39.54 | 13 / 1 | |
| 5.39.53 | 13 / 1 | |
| 5.39.52 | 13 / 1 | |
| 5.39.51 | 13 / 1 | |
| 5.39.50 | 23 / 1 | |
| 5.39.49 | 23 / 1 | |
| 5.39.48 | 23 / 1 | |
| 5.39.47 | 23 / 1 | |
| 5.39.46 | 23 / 1 | |
| 5.39.45 | 23 / 1 | |
| 5.39.44 | 23 / 1 | |
| 5.39.43 | 23 / 1 | |
| 5.39.42 | 23 / 1 | |
| 5.39.41 | 23 / 1 | |
| 5.39.40 | 23 / 1 | |
| 5.39.39 | 23 / 1 | |
| 5.39.38 | 23 / 1 | |
| 5.39.37 | 23 / 1 | |
| 5.39.36 | 23 / 1 | |
| 5.39.35 | 23 / 1 | |
| 5.39.34 | 23 / 1 | |
| 5.39.33 | 23 / 1 | |
| 5.39.32 | 23 / 1 | |
| 5.39.31 | 23 / 1 | |
| 5.39.30 | 23 / 1 | |
| 5.39.29 | 23 / 1 | |
| 5.39.28 | 23 / 1 | |
| 5.39.27 | 23 / 1 | |
| 5.39.26 | 23 / 1 | |
| 5.39.25 | 23 / 1 | |
| 5.39.24 | 23 / 1 | |
| 5.39.23 | 23 / 1 | |
| 5.39.22 | 23 / 1 | |
| 5.39.21 | 23 / 1 | |
| 5.39.20 | 23 / 1 | |
| 5.39.19 | 23 / 1 | |
| 5.39.18 | 23 / 1 | |
| 5.39.17 | 23 / 1 | |
| 5.39.16 | 23 / 1 | |
| 5.39.15 | 23 / 1 | |
| 5.39.14 | 23 / 1 | |
| 5.39.13 | 23 / 1 | |
| 5.39.12 | 23 / 1 | |
| 5.39.11 | 23 / 1 | |
| 5.39.10 | 23 / 1 | |
| 5.39.9 | 23 / 1 | |
| 5.39.8 | 23 / 1 | |
| 5.39.7 | 23 / 1 | |
| 5.39.6 | 23 / 1 | |
| 5.39.5 | 23 / 1 | |
| 5.39.4 | 23 / 1 | |
| 5.39.3 | 23 / 1 | |
| 5.39.2 | 23 / 1 | |
| 5.39.1 | 23 / 1 | |
| 5.39.0 | 23 / 1 | |
| 5.38.5 | 23 / 1 | |
| 5.38.4 | 23 / 1 | |
| 5.38.3 | 23 / 1 | |
| 5.38.2 | 23 / 1 | |
| 5.38.1 | 23 / 1 | |
| 5.38.0 | 23 / 1 | |
| 5.37.26 | 23 / 1 | |
| 5.37.25 | 23 / 1 | |
| 5.37.24 | 23 / 1 | |
| 5.37.23 | 23 / 1 | |
| 5.37.22 | 23 / 1 | |
| 5.37.21 | 23 / 1 | |
| 5.37.20 | 23 / 1 | |
| 5.37.19 | 23 / 1 | |
| 5.37.18 | 23 / 1 | |
| 5.37.17 | 23 / 1 | |
| 5.37.16 | 23 / 1 | |
| 5.37.15 | 23 / 1 | |
| 5.37.14 | 23 / 1 | |
| 5.37.13 | 23 / 1 |
v5.41.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.8
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.7
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.6
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.5
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v5.41.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.41.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.40.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.40.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.39.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.