@microsoft/rush-lib
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Passes own env into build operation hooks; core Rush behavior, no exfil destination. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Resolves internal rush-lib module paths; documented plugin loading. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Copies env for subprocess config; standard build tooling. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Compiles cache-key template string, not external input. | ai | |
| dependencies | unvetted-dep:@rushstack/rush-azure-storage-build-cache-plugin | AI (dependencies): First-party rushstack sibling package. | ai | |
| phantom-deps | phantom-dep:rxjs | AI (phantom-deps): Used via config, expected in monorepo build tool. | ai | |
| phantom-deps | phantom-dep:@yarnpkg/lockfile | AI (phantom-deps): Used via config, expected in monorepo build tool. | ai | |
| dependencies | unvetted-dep:@rushstack/npm-check-fork | AI (dependencies): First-party rushstack sibling package, versioned in lockstep. | ai | |
| phantom-deps | phantom-dep:@rushstack/rush-http-build-cache-plugin | AI (phantom-deps): Plugin referenced via config, not direct import. | ai | |
| phantom-deps | phantom-dep:@rushstack/rush-amazon-s3-build-cache-plugin | AI (phantom-deps): Plugin referenced via config, not direct import. | ai | |
| phantom-deps | phantom-dep:@rushstack/rush-azure-storage-build-cache-plugin | AI (phantom-deps): Plugin referenced via config, not direct import. | ai | |
| phantom-deps | phantom-dep:https-proxy-agent | AI (phantom-deps): Used via config, expected in monorepo build tool. | ai | |
| dependencies | unvetted-dep:@rushstack/rush-pnpm-kit-v8 | AI (dependencies): First-party rushstack sibling package. | ai | |
| dependencies | unvetted-dep:@rushstack/rush-pnpm-kit-v9 | AI (dependencies): First-party rushstack sibling package. | ai | |
| dependencies | unvetted-dep:@rushstack/rush-pnpm-kit-v10 | AI (dependencies): First-party rushstack sibling package. | ai |
Versions (showing 39 of 39)
| Version | Deps | Published |
|---|---|---|
| 5.178.0 | 42 / 17 | |
| 5.177.2 | 42 / 17 | |
| 5.177.1 | 42 / 17 | |
| 5.177.0 | 42 / 17 | |
| 5.176.0 | 42 / 17 | |
| 5.175.1 | 42 / 17 | |
| 5.175.0 | 42 / 17 | |
| 5.174.0 | 42 / 19 | |
| 5.173.0 | 42 / 19 | |
| 5.172.1 | 42 / 19 | |
| 5.172.0 | 42 / 19 | |
| 5.171.0 | 42 / 19 | |
| 5.170.1 | 42 / 19 | |
| 5.170.0 | 42 / 19 | |
| 5.169.3 | 42 / 19 | |
| 5.169.2 | 42 / 19 | |
| 5.169.1 | 42 / 19 | |
| 5.169.0 | 42 / 19 | |
| 5.168.0 | 42 / 19 | |
| 5.167.0 | 42 / 19 | |
| 5.166.0 | 42 / 20 | |
| 5.165.0 | 42 / 20 | |
| 5.164.0 | 42 / 21 | |
| 5.130.2 | 39 / 19 | |
| 5.130.1 | 39 / 19 | |
| 5.130.0 | 39 / 19 | |
| 5.129.7 | 39 / 19 | |
| 5.129.6 | 39 / 19 | |
| 5.129.5 | 39 / 19 | |
| 5.129.4 | 39 / 19 | |
| 5.129.3 | 39 / 19 | |
| 5.129.2 | 39 / 19 | |
| 5.129.1 | 39 / 19 | |
| 5.129.0 | 39 / 19 | |
| 5.128.5 | 39 / 19 | |
| 5.128.4 | 39 / 19 | |
| 5.128.3 | 39 / 19 | |
| 5.128.2 | 39 / 19 | |
| 5.128.1 | 39 / 19 |
v5.178.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.177.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.177.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.177.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.176.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.175.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.175.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.174.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.173.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.172.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.172.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.171.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.170.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.170.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.169.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.169.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.169.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.169.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.168.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.167.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.166.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.165.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.164.0
7 findingsSpreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-commonjs/cli/scriptActions/PhasedScriptAction.js#L405 403 | createEnvironmentForOperation: this.hooks.createEnvironmentForOperation.isUsed() 404 | ? (record) => { > 405 | return this.hooks.createEnvironmentForOperation.call({ ...process.env }, record); 406 | } 407 | : undefined,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-commonjs/logic/EventHooksManager.js#L35 33 | scripts.forEach((script) => { 34 | try { > 35 | const environment = { ...process.env }; 36 | // NOTE: Do NOT expose this variable to other subprocesses besides telemetry hooks. We do NOT want 37 | // child processes to inspect Rush's raw command line and magically change their behavior in a way
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-commonjs/logic/incremental/InputsSnapshot.js#L65 63 | */ 64 | constructor(params) { > 65 | const { additionalHashes, environment = { ...process.env }, globalAdditionalFiles, hashes, hasUncommittedChanges 66 | const projectMetadataMap = new Map(); 67 | for (const [project, record] of params.projectMap) {
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-esnext/cli/scriptActions/PhasedScriptAction.js#L369 367 | createEnvironmentForOperation: this.hooks.createEnvironmentForOperation.isUsed() 368 | ? (record) => { > 369 | return this.hooks.createEnvironmentForOperation.call({ ...process.env }, record); 370 | } 371 | : undefined,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-esnext/logic/EventHooksManager.js#L32 30 | scripts.forEach((script) => { 31 | try { > 32 | const environment = { ...process.env }; 33 | // NOTE: Do NOT expose this variable to other subprocesses besides telemetry hooks. We do NOT want 34 | // child processes to inspect Rush's raw command line and magically change their behavior in a way
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/microsoft/rushstack/blob/b65048ddf033b9a41624a1a8832a2f117a1cedcd/lib-esnext/logic/incremental/InputsSnapshot.js#L26 24 | */ 25 | constructor(params) { > 26 | const { additionalHashes, environment = { ...process.env }, globalAdditionalFiles, hashes, hasUncommittedChanges 27 | const projectMetadataMap = new Map(); 28 | for (const [project, record] of params.projectMap) {
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.130.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.130.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.130.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.129.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.128.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.128.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.128.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.128.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.128.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.