@papit/build
Build tool for @papit packages — opinionated, fast, and designed to work seamlessly inside any Papit-based workspace.
5
Versions
LicenseRef-Papit-1.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
papit
Keywords
papitnodetypescriptbuild
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing is confirmed by SLSA/Sigstore attestation; consistent with the package's repo and org. | ai | |
| typosquat | typosquat.levenshtein:esbuild | AI (typosquat): Scoped @papit/build wraps esbuild as a peer dep; not impersonating it. | ai | |
| phantom-deps | phantom-dep:@papit/terminal | AI (phantom-deps): Same-org sibling dependency; indirect usage pattern is expected in this monorepo. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @papit/build is a monorepo build tool; Levenshtein match to uuid is coincidental. | ai | |
| phantom-deps | phantom-dep:@papit/bundle-ts | AI (phantom-deps): Same-org sibling; indirect usage expected. | ai | |
| phantom-deps | phantom-dep:@papit/data-structure | AI (phantom-deps): Same-org sibling; indirect usage expected. | ai | |
| phantom-deps | phantom-dep:@papit/bundle-js | AI (phantom-deps): Same-org sibling; indirect usage expected. | ai |