@stdlib/math-base-assert-is-finitef
Test if a single-precision floating-point numeric value is finite.
3
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
stdlib-botkgryteplaneshifterrreusser
Keywords
stdlibstdmathassertionassertutilitiesutilityutilsutilmathmathematicsieee754floating-pointfloatsinglenumbernumericfiniteisisfiniteftypecheck
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@stdlib/napi-argv | AI (phantom-deps): Native addon deps used via C/N-API; not directly imported in JS but legitimately declared for native build. | ai | |
| phantom-deps | phantom-dep:@stdlib/napi-export | AI (phantom-deps): Same N-API pattern; stable false positive for this stdlib native binding package. | ai | |
| phantom-deps | phantom-dep:@stdlib/napi-argv-float | AI (phantom-deps): Same N-API pattern; stable false positive for this stdlib native binding package. | ai | |
| phantom-deps | phantom-dep:@stdlib/napi-create-int32 | AI (phantom-deps): Same N-API pattern; stable false positive for this stdlib native binding package. | ai | |
| phantom-deps | phantom-dep:@stdlib/utils-library-manifest | AI (phantom-deps): Library manifest utility used at build/native level, not JS import; stable FP for stdlib packages. | ai | |
| provenance | no-provenance | AI (provenance): stdlib-bot publishes many packages without provenance; consistent across the ecosystem, not a risk signal here. | ai |
v0.2.2
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.1
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.