← Home

@modern-js/polyfill-lib

1
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

webinfrabottqmatargeralyimingjfeawait_oqiuzeyuanc95caohuilinkky_kongjiacongbytednpmdexteryy

Keywords

reactframeworkmodernmodern.js

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:new-function-constructor AI (semgrep): Fires in polyfill test files asserting Array.isArray behavior — not dynamic code execution. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires in Reflect polyfill test files testing the Reflect API itself — not obfuscation. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Polyfill aggregator references deps via config files; phantom-dep pattern is expected for this package type. ai
phantom-deps phantom-dep:intl AI (phantom-deps): Same as above — polyfill deps referenced via config, not direct imports. ai
phantom-deps phantom-dep:json3 AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:unorm AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:Base64 AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:rimraf AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:html5shiv AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:usertiming AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:wicg-inert AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:picturefill AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:js-polyfills AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:whatwg-fetch AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:abort-controller AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:web-animations-js AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:event-source-polyfill AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:mutationobserver-shim AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:audio-context-polyfill AI (phantom-deps): Same as above. ai
phantom-deps phantom-dep:@juggle/resize-observer AI (phantom-deps): Same as above. ai

Versions (showing 1 of 1)

Version Deps Published
1.0.2 43 / 28

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.