← Home

@microsoft/rush-lib

39
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

microsoft1esmicrosoft-oss-releasesodspnpm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-spread AI (semgrep): Passes own env into build operation hooks; core Rush behavior, no exfil destination. ai
semgrep semgrep:dynamic-require AI (semgrep): Resolves internal rush-lib module paths; documented plugin loading. ai
semgrep semgrep:env-bulk-read AI (semgrep): Copies env for subprocess config; standard build tooling. ai
semgrep semgrep:new-function-constructor AI (semgrep): Compiles cache-key template string, not external input. ai
dependencies unvetted-dep:@rushstack/rush-azure-storage-build-cache-plugin AI (dependencies): First-party rushstack sibling package. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): Used via config, expected in monorepo build tool. ai
phantom-deps phantom-dep:@yarnpkg/lockfile AI (phantom-deps): Used via config, expected in monorepo build tool. ai
dependencies unvetted-dep:@rushstack/npm-check-fork AI (dependencies): First-party rushstack sibling package, versioned in lockstep. ai
phantom-deps phantom-dep:@rushstack/rush-http-build-cache-plugin AI (phantom-deps): Plugin referenced via config, not direct import. ai
phantom-deps phantom-dep:@rushstack/rush-amazon-s3-build-cache-plugin AI (phantom-deps): Plugin referenced via config, not direct import. ai
phantom-deps phantom-dep:@rushstack/rush-azure-storage-build-cache-plugin AI (phantom-deps): Plugin referenced via config, not direct import. ai
phantom-deps phantom-dep:https-proxy-agent AI (phantom-deps): Used via config, expected in monorepo build tool. ai
dependencies unvetted-dep:@rushstack/rush-pnpm-kit-v8 AI (dependencies): First-party rushstack sibling package. ai
dependencies unvetted-dep:@rushstack/rush-pnpm-kit-v9 AI (dependencies): First-party rushstack sibling package. ai
dependencies unvetted-dep:@rushstack/rush-pnpm-kit-v10 AI (dependencies): First-party rushstack sibling package. ai

Versions (showing 39 of 39)

Version Deps Published
5.178.0 42 / 17
5.177.2 42 / 17
5.177.1 42 / 17
5.177.0 42 / 17
5.176.0 42 / 17
5.175.1 42 / 17
5.175.0 42 / 17
5.174.0 42 / 19
5.173.0 42 / 19
5.172.1 42 / 19
5.172.0 42 / 19
5.171.0 42 / 19
5.170.1 42 / 19
5.170.0 42 / 19
5.169.3 42 / 19
5.169.2 42 / 19
5.169.1 42 / 19
5.169.0 42 / 19
5.168.0 42 / 19
5.167.0 42 / 19
5.166.0 42 / 20
5.165.0 42 / 20
5.164.0 42 / 21
5.130.2 39 / 19
5.130.1 39 / 19
5.130.0 39 / 19
5.129.7 39 / 19
5.129.6 39 / 19
5.129.5 39 / 19
5.129.4 39 / 19
5.129.3 39 / 19
5.129.2 39 / 19
5.129.1 39 / 19
5.129.0 39 / 19
5.128.5 39 / 19
5.128.4 39 / 19
5.128.3 39 / 19
5.128.2 39 / 19
5.128.1 39 / 19

v5.178.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.177.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.177.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.177.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.176.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.175.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.175.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.174.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.173.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.172.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.172.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.171.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.170.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.170.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.169.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.169.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.169.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.169.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.168.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.167.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.166.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.165.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.164.0

7 findings
HIGH env-spread: lib-commonjs/cli/scriptActions/PhasedScriptAction.js:405 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-commonjs/cli/scriptActions/PhasedScriptAction.js#L405 403 | createEnvironmentForOperation: this.hooks.createEnvironmentForOperation.isUsed() 404 | ? (record) => { > 405 | return this.hooks.createEnvironmentForOperation.call({ ...process.env }, record); 406 | } 407 | : undefined,

HIGH env-spread: lib-commonjs/logic/EventHooksManager.js:35 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-commonjs/logic/EventHooksManager.js#L35 33 | scripts.forEach((script) => { 34 | try { > 35 | const environment = { ...process.env }; 36 | // NOTE: Do NOT expose this variable to other subprocesses besides telemetry hooks. We do NOT want 37 | // child processes to inspect Rush's raw command line and magically change their behavior in a way

HIGH env-spread: lib-commonjs/logic/incremental/InputsSnapshot.js:65 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-commonjs/logic/incremental/InputsSnapshot.js#L65 63 | */ 64 | constructor(params) { > 65 | const { additionalHashes, environment = { ...process.env }, globalAdditionalFiles, hashes, hasUncommittedChanges 66 | const projectMetadataMap = new Map(); 67 | for (const [project, record] of params.projectMap) {

HIGH env-spread: lib-esnext/cli/scriptActions/PhasedScriptAction.js:369 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-esnext/cli/scriptActions/PhasedScriptAction.js#L369 367 | createEnvironmentForOperation: this.hooks.createEnvironmentForOperation.isUsed() 368 | ? (record) => { > 369 | return this.hooks.createEnvironmentForOperation.call({ ...process.env }, record); 370 | } 371 | : undefined,

HIGH env-spread: lib-esnext/logic/EventHooksManager.js:32 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-esnext/logic/EventHooksManager.js#L32 30 | scripts.forEach((script) => { 31 | try { > 32 | const environment = { ...process.env }; 33 | // NOTE: Do NOT expose this variable to other subprocesses besides telemetry hooks. We do NOT want 34 | // child processes to inspect Rush's raw command line and magically change their behavior in a way

HIGH env-spread: lib-esnext/logic/incremental/InputsSnapshot.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-esnext/logic/incremental/InputsSnapshot.js#L26 24 | */ 25 | constructor(params) { > 26 | const { additionalHashes, environment = { ...process.env }, globalAdditionalFiles, hashes, hasUncommittedChanges 27 | const projectMetadataMap = new Map(); 28 | for (const [project, record] of params.projectMap) {

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.130.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.130.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.130.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.129.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.128.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.128.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.128.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.128.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.128.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.