@pob/rollup-esbuild
rollup configuration with typescript for pob
9
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
churpeau
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@rollup/plugin-run | AI (dependencies): Official @rollup org plugin; stable dependency in this build-tool package. | ai | |
| dependencies | unvetted-dep:rollup-config-external-dependencies | AI (dependencies): Known rollup ecosystem utility; consistent dependency across versions of this package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with consistent authorship; lack of provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): esbuild is listed as a direct dependency in package.json and used as a runtime binary; phantom-dep false positive for this package. | ai |