@modern-js/babel-compiler
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Shared monorepo README linkdump is a stable FP for this legitimate Modern.js sub-package. | ai |
Versions (showing 100 of 102)
| Version | Deps | Published |
|---|---|---|
| 2.71.1 | 3 / 10 | |
| 2.71.0 | 3 / 10 | |
| 2.70.8 | 3 / 10 | |
| 2.70.7 | 3 / 10 | |
| 2.70.6 | 3 / 10 | |
| 2.70.5 | 3 / 10 | |
| 2.70.4 | 3 / 10 | |
| 2.70.3 | 3 / 10 | |
| 2.70.2 | 3 / 10 | |
| 2.70.1 | 3 / 10 | |
| 2.70.0 | 3 / 10 | |
| 2.69.7 | 3 / 10 | |
| 2.69.6 | 3 / 10 | |
| 2.69.5 | 3 / 10 | |
| 2.69.4 | 3 / 10 | |
| 2.69.3 | 3 / 10 | |
| 2.69.2 | 3 / 10 | |
| 2.69.1 | 3 / 10 | |
| 2.69.0 | 3 / 10 | |
| 2.68.20 | 3 / 10 | |
| 2.68.19 | 3 / 10 | |
| 2.68.18 | 3 / 10 | |
| 2.68.17 | 3 / 10 | |
| 2.68.16 | 3 / 10 | |
| 2.68.15 | 3 / 10 | |
| 2.68.14 | 3 / 10 | |
| 2.68.13 | 3 / 10 | |
| 2.68.12 | 3 / 10 | |
| 2.68.11 | 3 / 10 | |
| 2.68.10 | 3 / 10 | |
| 2.68.9 | 3 / 10 | |
| 2.68.8 | 3 / 10 | |
| 2.68.7 | 3 / 10 | |
| 2.68.6 | 3 / 10 | |
| 2.68.5 | 3 / 10 | |
| 2.68.4 | 3 / 10 | |
| 2.68.3 | 3 / 10 | |
| 2.68.2 | 3 / 10 | |
| 2.68.1 | 3 / 10 | |
| 2.68.0 | 3 / 10 | |
| 2.67.11 | 3 / 10 | |
| 2.67.10 | 3 / 10 | |
| 2.67.9 | 3 / 10 | |
| 2.67.8 | 3 / 10 | |
| 2.67.7 | 3 / 10 | |
| 2.67.6 | 3 / 10 | |
| 2.67.5 | 3 / 10 | |
| 2.67.4 | 3 / 10 | |
| 2.67.2 | 3 / 10 | |
| 2.67.1 | 3 / 10 | |
| 2.66.0 | 3 / 10 | |
| 2.65.5 | 3 / 10 | |
| 2.65.3 | 3 / 10 | |
| 2.65.2 | 3 / 10 | |
| 2.65.1 | 3 / 10 | |
| 2.65.0 | 3 / 10 | |
| 2.64.3 | 3 / 10 | |
| 2.64.2 | 3 / 10 | |
| 2.64.1 | 3 / 10 | |
| 2.64.0 | 3 / 10 | |
| 2.63.7 | 3 / 10 | |
| 2.63.6 | 3 / 10 | |
| 2.63.5 | 3 / 10 | |
| 2.63.4 | 3 / 10 | |
| 2.63.3 | 3 / 10 | |
| 2.63.2 | 3 / 10 | |
| 2.63.1 | 3 / 10 | |
| 2.63.0 | 3 / 10 | |
| 2.62.1 | 3 / 10 | |
| 2.62.0 | 3 / 10 | |
| 2.61.0 | 3 / 10 | |
| 2.60.6 | 3 / 10 | |
| 2.60.5 | 3 / 10 | |
| 2.60.4 | 3 / 10 | |
| 2.60.3 | 3 / 10 | |
| 2.60.2 | 3 / 10 | |
| 2.60.1 | 3 / 10 | |
| 2.60.0 | 3 / 10 | |
| 2.59.0 | 3 / 10 | |
| 2.58.3 | 3 / 10 | |
| 2.58.2 | 3 / 10 | |
| 2.58.1 | 3 / 10 | |
| 2.58.0 | 3 / 10 | |
| 2.57.1 | 3 / 10 | |
| 2.57.0 | 3 / 10 | |
| 2.56.2 | 3 / 10 | |
| 2.56.1 | 3 / 10 | |
| 2.56.0 | 3 / 10 | |
| 2.55.0 | 3 / 10 | |
| 2.54.6 | 3 / 10 | |
| 2.54.5 | 3 / 10 | |
| 2.54.4 | 3 / 10 | |
| 2.54.3 | 3 / 10 | |
| 2.54.2 | 3 / 10 | |
| 2.54.1 | 3 / 10 | |
| 2.54.0 | 3 / 10 | |
| 2.53.0 | 3 / 10 | |
| 2.52.0 | 3 / 10 | |
| 2.51.0 | 3 / 10 | |
| 2.50.0 | 3 / 10 |
v2.71.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.67.2
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.67.1
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.66.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.65.5
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.65.3
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.65.2
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.65.1
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.65.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.64.3
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.64.2
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.64.1
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.64.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.63.7
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.63.6
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.63.5
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.63.4
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.63.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.63.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.63.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.63.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.62.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.62.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.61.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.60.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.60.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.60.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.60.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.60.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.60.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.60.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.59.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.58.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.58.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.58.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.58.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.57.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.57.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.56.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.56.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.56.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.55.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.54.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.54.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.54.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.54.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.54.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.54.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.54.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.53.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.52.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.51.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.50.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.