@parcel/hash
24
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
devongovett
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): @parcel/hash is the official Parcel bundler hashing utility under the @parcel npm scope; no typosquat relationship to 'hapi' exists. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established native binding package; missing description is a minor metadata gap, not a malice indicator. | ai | |
| provenance | no-provenance | AI (provenance): Provenance attestation is a best-practice gap; not a blocker for an established, well-maintained package. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): @parcel/hash is a NAPI-RS native addon; bundled .node binaries are the expected delivery mechanism for prebuilt platform-specific binaries. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is the standard NAPI-RS platform-selection pattern, loading one of the bundled .node files based on OS/arch — not arbitrary module loading. | ai | |
| dependencies | unvetted-dep:detect-libc | AI (dependencies): detect-libc is a well-known utility used by native addons to distinguish glibc vs musl Linux; its use here is expected and benign. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 2.9.3 | 1 / 2 | |
| 2.9.2 | 1 / 2 | |
| 2.9.1 | 1 / 2 | |
| 2.9.0 | 1 / 2 | |
| 2.8.3 | 2 / 2 | |
| 2.8.2 | 2 / 2 | |
| 2.8.1 | 2 / 2 | |
| 2.8.0 | 2 / 2 | |
| 2.7.0 | 2 / 2 | |
| 2.6.2 | 2 / 2 | |
| 2.6.1 | 2 / 2 | |
| 2.6.0 | 2 / 2 | |
| 2.5.0 | 2 / 2 | |
| 2.4.1 | 2 / 2 | |
| 2.4.0 | 2 / 2 | |
| 2.3.2 | 2 / 2 | |
| 2.3.1 | 2 / 2 | |
| 2.3.0 | 2 / 2 | |
| 2.2.1 | 2 / 2 | |
| 2.2.0 | 2 / 2 | |
| 2.1.1 | 2 / 2 | |
| 2.1.0 | 2 / 2 | |
| 2.0.1 | 2 / 2 | |
| 2.0.0 | 2 / 2 |