@oxc-transform/binding-linux-ppc64-gnu
Oxc Transformer Node API
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): Platform-specific native binding package; .node binary is the intended artifact, published with SLSA provenance. | ai | |
| bogus-package | bogus-package | AI (bogus-package): No-dep, minimal-README pattern is expected for a platform-specific optional dependency sub-package. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 0.140.0 | 0 / 0 | |
| 0.139.0 | 0 / 0 | |
| 0.138.0 | 0 / 0 | |
| 0.137.0 | 0 / 0 | |
| 0.136.0 | 0 / 0 | |
| 0.135.0 | 0 / 0 | |
| 0.134.0 | 0 / 0 | |
| 0.133.0 | 0 / 0 | |
| 0.132.0 | 0 / 0 | |
| 0.131.0 | 0 / 0 | |
| 0.130.0 | 0 / 0 | |
| 0.129.0 | 0 / 0 | |
| 0.128.0 | 0 / 0 | |
| 0.121.0 | 0 / 0 | |
| 0.120.0 | 0 / 0 | |
| 0.119.0 | 0 / 0 | |
| 0.118.0 | 0 / 0 | |
| 0.117.0 | 0 / 0 | |
| 0.116.0 | 0 / 0 | |
| 0.115.0 | 0 / 0 | |
| 0.114.0 | 0 / 0 | |
| 0.112.0 | 0 / 0 | |
| 0.111.0 | 0 / 0 | |
| 0.110.0 | 0 / 0 | |
| 0.109.0 | 0 / 0 | |
| 0.108.0 | 0 / 0 | |
| 0.107.0 | 0 / 0 | |
| 0.106.0 | 0 / 0 | |
| 0.104.0 | 0 / 0 |
v0.140.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.139.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.138.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.137.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.121.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.120.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.119.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.118.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.117.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.116.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.115.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.114.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.112.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.111.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.110.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.109.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.108.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.107.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.106.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (boshen) on 2025-12-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.