← Home

@smoothbricks/lmao

This library was generated with [Nx](https://nx.dev).

8
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

niko_nt2sergeybricksdannwilson

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Change is manual→GitHub Actions CI/CD with SLSA attestation; provenance improvement, not compromise. ai
npm-metadata bundled-binaries AI (npm-metadata): Self-authored Zig-compiled wasm allocator, matches package's own build:wasm script. ai
publish-pattern new-deps-added AI (publish-pattern): typia is an established validation library, no exfil/exec behavior. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): All 84 instances are in test files using Reflect.get() for test introspection; not present in runtime code. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used in test assertions to validate generated JS code is syntactically valid; not in runtime paths. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a declared runtime dependency used implicitly by TypeScript compilation output; stable false positive. ai

Versions (showing 8 of 8)

Version Deps Published
0.2.2 7 / 2
0.2.1 7 / 2
0.2.0 6 / 2
0.1.4 6 / 2
0.1.3 6 / 2
0.1.2 6 / 2
0.1.1 6 / 2
0.1.0 6 / 2

v0.2.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/allocator.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/allocator.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

2 findings
HIGH Publisher changed: sergeybricks → GitHub Actions (on 2026-04-28) provenance

This version was published by a different npm account than previous versions on 2026-04-28. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.