@node-minify/core
9
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
srod
Keywords
compressorminifyminifier
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publishing is consistent with CI automation by the original repo owner (srod/node-minify); SLSA attestation confirms integrity. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by CI-automated publish with SLSA provenance; consistent with a maintainer resuming development via automation. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Legitimate scoped package in the node-minify monorepo; name similarity to 'cors' is coincidental. | ai |