← Home

@stdlib/string-replace

Replace search occurrences with a replacement string.

17
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

stdlib-botkgryteplaneshifterrreusser

Keywords

stdlibstdstringutilitiesutilityutilsutilstringstrsearchreplaceregexregular expressionregexpregularexpression

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata url-dep:tape AI (npm-metadata): Dev-only test dependency pinned to a fork; no runtime impact. ai
phantom-deps phantom-dep:@stdlib/cli AI (phantom-deps): Same-org stdlib dep, used by CLI bin; stable false positive. ai
phantom-deps phantom-dep:@stdlib/regexp-eol AI (phantom-deps): Same-org stdlib dep; stable false positive. ai
phantom-deps phantom-dep:@stdlib/fs-read-file AI (phantom-deps): Same-org stdlib dep; stable false positive. ai
phantom-deps phantom-dep:@stdlib/process-read-stdin AI (phantom-deps): Same-org stdlib dep; stable false positive. ai
phantom-deps phantom-dep:@stdlib/streams-node-stdin AI (phantom-deps): Same-org stdlib dep; stable false positive. ai
phantom-deps phantom-dep:@stdlib/assert-is-regexp-string AI (phantom-deps): Same-org stdlib dep; stable false positive. ai
phantom-deps phantom-dep:@stdlib/utils-regexp-from-string AI (phantom-deps): Same-org stdlib dep; stable false positive. ai
phantom-deps phantom-dep:@stdlib/error-tools-fmtprodmsg AI (phantom-deps): Same-org stdlib dep declared for prod error formatting; stable false positive for this package family. ai

Versions (showing 17 of 17)

Version Deps Published
0.2.3 7 / 0
0.2.2 7 / 0
0.2.1 6 / 0
0.2.0 6 / 6
0.1.1 6 / 6
0.1.0 6 / 6
0.0.11 12 / 11
0.0.10 11 / 11
0.0.9 11 / 11
0.0.8 11 / 11
0.0.7 11 / 11
0.0.6 11 / 11
0.0.5 11 / 11
0.0.4 11 / 11
0.0.3 11 / 11
0.0.2 11 / 10
0.0.1 11 / 10

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.