@rspack-debug/core
Fast Rust-based bundler for the web with a modernized webpack API
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/index.js | AI (source-diff): Base64 strings are embedded WASM binaries (xxhash64/md4) — standard rspack bundler pattern, not obfuscated malware. | ai | |
| source-diff | encoded-string-file:dist/worker.js | AI (source-diff): Same WASM binary embedding pattern as dist/index.js; stable across rspack versions. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @rspack-debug/core is not a typosquat of cors; name similarity is coincidental. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 2.1.4 | 1 / 19 | |
| 2.1.3 | 1 / 19 | |
| 2.1.2 | 1 / 19 | |
| 2.1.1 | 1 / 19 | |
| 2.1.0 | 1 / 19 | |
| 2.0.8 | 1 / 19 | |
| 2.0.7 | 1 / 19 | |
| 2.0.6 | 1 / 19 | |
| 2.0.5 | 1 / 19 | |
| 2.0.4 | 1 / 19 | |
| 2.0.3 | 1 / 19 | |
| 2.0.2 | 1 / 19 | |
| 2.0.1 | 1 / 20 | |
| 2.0.0 | 1 / 20 | |
| 1.7.9 | 3 / 17 | |
| 1.7.8 | 3 / 17 | |
| 1.7.6 | 3 / 17 | |
| 1.7.5 | 3 / 17 | |
| 1.7.4 | 3 / 17 | |
| 1.7.3 | 3 / 17 | |
| 1.7.2 | 3 / 17 | |
| 1.7.1 | 3 / 17 | |
| 1.7.0 | 3 / 17 | |
| 1.6.7 | 3 / 17 | |
| 1.6.6 | 3 / 17 | |
| 1.6.5 | 3 / 17 | |
| 1.6.4 | 3 / 17 | |
| 1.6.2 | 3 / 17 |
v2.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.