@patternslib/patternslib
2
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
pilzjcbrandfulvthetalessandro.pisaaskesemanngoibhniu
Keywords
patternslib
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:new-function-constructor | AI (semgrep): Explicitly documented as CSP-unsafe with a warning; intentional template helper, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:luxon | AI (phantom-deps): Large UI library; phantom-dep heuristic unreliable for webpack-bundled packages with optional/lazy imports. | ai | |
| phantom-deps | phantom-dep:showdown | AI (phantom-deps): Same as above — config-referenced deps in a bundled library are not phantom deps in the malicious sense. | ai | |
| phantom-deps | phantom-dep:moment-timezone | AI (phantom-deps): Same as above. | ai | |
| phantom-deps | phantom-dep:showdown-prettify | AI (phantom-deps): Same as above. | ai | |
| phantom-deps | phantom-dep:@fullcalendar/adaptive | AI (phantom-deps): Same as above. | ai |