← Home

@stdlib/math-base-special-ldexp

Multiply a double-precision floating-point number by an integer power of two.

15
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

stdlib-botkgryteplaneshifterrreusser

Keywords

stdlibstdmathmathmathematicsfrexpldexploadexponentdoubledblfloatfloating-pointnumberieee754

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:install AI (install-scripts): Standard node-gyp rebuild pattern across stdlib native modules. ai
npm-metadata url-dep:tap-min AI (npm-metadata): Long-standing devDependency git fork used across stdlib packages. ai
phantom-deps phantom-dep:@stdlib/math-base-special-abs AI (phantom-deps): Same-org stdlib submodule, common false positive. ai
phantom-deps phantom-dep:@stdlib/number-float32-base-to-word AI (phantom-deps): Same-org stdlib submodule, common false positive. ai
npm-metadata url-dep:tape AI (npm-metadata): Dev-only test dependency pinned to a maintainer fork; not shipped, no exec risk. ai
provenance no-provenance AI (provenance): stdlib-bot publishes without Sigstore provenance; consistent across all stdlib packages. ai
phantom-deps phantom-dep:@stdlib/utils-library-manifest AI (phantom-deps): stdlib manifest utility; declared for tooling, not imported at runtime — stable false positive for this package. ai

Versions (showing 15 of 15)

Version Deps Published
0.2.5 14 / 0
0.2.4 14 / 0
0.2.3 16 / 0
0.2.2 16 / 0
0.2.1 16 / 0
0.2.0 16 / 12
0.1.0 16 / 11
0.0.8 13 / 10
0.0.7 13 / 10
0.0.6 13 / 10
0.0.5 13 / 10
0.0.4 13 / 10
0.0.3 13 / 10
0.0.2 13 / 10
0.0.1 13 / 10

v0.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

2 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp rebuild

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

2 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp rebuild

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

2 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp rebuild

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.