@parcel/transformer-js
49
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
devongovett
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Provenance attestation is optional; absence is not a security risk for established packages. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Monorepo package; missing description is common and not a malware indicator here. | ai | |
| dependencies | unvetted-dep:detect-libc | AI (dependencies): detect-libc is a standard utility for detecting Linux libc variant; used here to select the correct platform-specific .node binary. Expected and benign for native Node.js packages. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): @parcel/transformer-js ships platform-specific NAPI/SWC native bindings as its core functionality; bundled .node files are expected and documented. | ai | |
| phantom-deps | phantom-dep:regenerator-runtime | AI (phantom-deps): regenerator-runtime is used by SWC-transformed output at runtime, not directly imported in source. Standard pattern for SWC-based transformers. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in native.js is the standard NAPI multi-platform binary loader pattern, constructing a filename from platform/arch to load the correct .node file. | ai | |
| phantom-deps | phantom-dep:@swc/helpers | AI (phantom-deps): @swc/helpers is a runtime dependency injected by the SWC compiler into transformed output, not directly imported in JS source. This is expected behavior. | ai |
Versions (showing 49 of 49)
| Version | Deps | Published |
|---|---|---|
| 2.16.4 | 11 / 0 | |
| 2.16.3 | 11 / 0 | |
| 2.16.2 | 11 / 0 | |
| 2.16.1 | 11 / 0 | |
| 2.16.0 | 11 / 0 | |
| 2.15.4 | 11 / 0 | |
| 2.15.3 | 11 / 0 | |
| 2.15.2 | 11 / 0 | |
| 2.15.1 | 11 / 0 | |
| 2.15.0 | 11 / 0 | |
| 2.14.4 | 11 / 0 | |
| 2.14.3 | 11 / 0 | |
| 2.14.2 | 11 / 0 | |
| 2.14.1 | 11 / 0 | |
| 2.14.0 | 11 / 0 | |
| 2.13.3 | 11 / 0 | |
| 2.13.2 | 11 / 0 | |
| 2.13.1 | 11 / 0 | |
| 2.13.0 | 11 / 0 | |
| 2.12.0 | 11 / 0 | |
| 2.11.0 | 11 / 0 | |
| 2.10.3 | 11 / 1 | |
| 2.10.2 | 11 / 1 | |
| 2.10.1 | 11 / 1 | |
| 2.10.0 | 11 / 1 | |
| 2.9.3 | 10 / 1 | |
| 2.9.2 | 10 / 1 | |
| 2.9.1 | 10 / 1 | |
| 2.9.0 | 10 / 1 | |
| 2.8.3 | 11 / 1 | |
| 2.8.2 | 11 / 1 | |
| 2.8.1 | 11 / 1 | |
| 2.8.0 | 11 / 1 | |
| 2.7.0 | 11 / 1 | |
| 2.6.2 | 11 / 1 | |
| 2.6.1 | 11 / 1 | |
| 2.6.0 | 11 / 1 | |
| 2.5.0 | 11 / 1 | |
| 2.4.1 | 11 / 1 | |
| 2.4.0 | 11 / 1 | |
| 2.3.2 | 11 / 1 | |
| 2.3.1 | 11 / 1 | |
| 2.3.0 | 11 / 1 | |
| 2.2.1 | 12 / 1 | |
| 2.2.0 | 12 / 1 | |
| 2.1.1 | 12 / 1 | |
| 2.1.0 | 12 / 1 | |
| 2.0.1 | 11 / 1 | |
| 2.0.0 | 11 / 1 |