@scandiumsys/owstra-engine
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): Tree-sitter wasm grammars are the package's stated parsing function. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Fires in test-taint fixture file, not shipped runtime code. | ai | |
| semgrep | semgrep:child-process-exec | AI (semgrep): Fires in test-taint fixture file, not shipped runtime code. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Scoped semver expression evaluator, not arbitrary code exec. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 1.3.0 | 7 / 4 | |
| 1.1.2 | 6 / 3 | |
| 1.0.2 | 6 / 3 | |
| 1.0.1 | 6 / 3 | |
| 1.0.0 | 6 / 3 |
v1.3.0
3 findingsPackage contains compiled binaries that could be backdoors: • grammars/tree-sitter-c.wasm • grammars/tree-sitter-cpp.wasm • grammars/tree-sitter-csharp.wasm • grammars/tree-sitter-dart.wasm • grammars/tree-sitter-dockerfile.wasm • grammars/tree-sitter-go.wasm • grammars/tree-sitter-java.wasm • grammars/tree-sitter-javascript.wasm • grammars/tree-sitter-json.wasm • grammars/tree-sitter-objc.wasm ... and 6 more
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: omoalfa.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.