@stdlib/math-base-special-ldexp
Multiply a double-precision floating-point number by an integer power of two.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:install | AI (install-scripts): Standard node-gyp rebuild pattern across stdlib native modules. | ai | |
| npm-metadata | url-dep:tap-min | AI (npm-metadata): Long-standing devDependency git fork used across stdlib packages. | ai | |
| phantom-deps | phantom-dep:@stdlib/math-base-special-abs | AI (phantom-deps): Same-org stdlib submodule, common false positive. | ai | |
| phantom-deps | phantom-dep:@stdlib/number-float32-base-to-word | AI (phantom-deps): Same-org stdlib submodule, common false positive. | ai | |
| npm-metadata | url-dep:tape | AI (npm-metadata): Dev-only test dependency pinned to a maintainer fork; not shipped, no exec risk. | ai | |
| provenance | no-provenance | AI (provenance): stdlib-bot publishes without Sigstore provenance; consistent across all stdlib packages. | ai | |
| phantom-deps | phantom-dep:@stdlib/utils-library-manifest | AI (phantom-deps): stdlib manifest utility; declared for tooling, not imported at runtime — stable false positive for this package. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 0.2.5 | 14 / 0 | |
| 0.2.4 | 14 / 0 | |
| 0.2.3 | 16 / 0 | |
| 0.2.2 | 16 / 0 | |
| 0.2.1 | 16 / 0 | |
| 0.2.0 | 16 / 12 | |
| 0.1.0 | 16 / 11 | |
| 0.0.8 | 13 / 10 | |
| 0.0.7 | 13 / 10 | |
| 0.0.6 | 13 / 10 | |
| 0.0.5 | 13 / 10 | |
| 0.0.4 | 13 / 10 | |
| 0.0.3 | 13 / 10 | |
| 0.0.2 | 13 / 10 | |
| 0.0.1 | 13 / 10 |
v0.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.1
2 findingsScript: node-gyp rebuild
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
2 findingsScript: node-gyp rebuild
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
2 findingsScript: node-gyp rebuild
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.