@pnpm/text.comments-parser
Extracts and inserts comments from/to text
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:strip-comments-strings | AI (phantom-deps): Genuine runtime dep; not scannable in bundled lib output. | ai | |
| provenance | no-provenance | AI (provenance): pnpm monorepo packages consistently lack Sigstore provenance; publisher has strong track record with 41 approved packages. This is a stable false positive for this package. | ai |
v1100.0.1
2 findingsThe directory `.` byte-matched 10 of 12 file(s) against @pnpm/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @pnpm/[email protected] before greenflagging.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.