← Home

@stdlib/utils-convert-path

Convert between POSIX and Windows paths.

14
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

stdlib-botkgryteplaneshifterrreusser

Keywords

stdlibstdutilsstdutilutilitiesutilityutilsutilconvertposixwindowswinlinuxunixwin32pathstringstr

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata url-dep:tape AI (npm-metadata): Dev-only test dependency URL pin, no runtime impact. ai
phantom-deps phantom-dep:@stdlib/cli AI (phantom-deps): Stdlib intra-org dep, CLI loaded indirectly; stable false positive. ai
phantom-deps phantom-dep:@stdlib/regexp-eol AI (phantom-deps): Stdlib intra-org dep pattern; not directly imported by design. ai
phantom-deps phantom-dep:@stdlib/fs-read-file AI (phantom-deps): Stdlib intra-org dep pattern; not directly imported by design. ai
phantom-deps phantom-dep:@stdlib/process-read-stdin AI (phantom-deps): Stdlib intra-org dep pattern; not directly imported by design. ai
phantom-deps phantom-dep:@stdlib/streams-node-stdin AI (phantom-deps): Stdlib intra-org dep pattern; not directly imported by design. ai
provenance no-provenance AI (provenance): Established stdlib-js package; provenance absence is consistent across the entire @stdlib namespace. ai
dependencies unvetted-dep:@stdlib/string-format AI (dependencies): First-party @stdlib dependency from the same trusted org. ai
dependencies unvetted-dep:@stdlib/string-replace AI (dependencies): First-party @stdlib dependency from the same trusted org. ai
dependencies unvetted-dep:@stdlib/assert-is-string AI (dependencies): First-party @stdlib dependency from the same trusted org. ai
dependencies unvetted-dep:@stdlib/string-base-lowercase AI (dependencies): First-party @stdlib dependency from the same trusted org. ai
dependencies unvetted-dep:@stdlib/regexp-extended-length-path AI (dependencies): First-party @stdlib dependency from the same trusted org. ai

Versions (showing 14 of 14)

Version Deps Published
0.2.3 6 / 0
0.2.2 6 / 0
0.2.1 5 / 0
0.2.0 5 / 4
0.1.1 5 / 4
0.1.0 5 / 4
0.0.8 9 / 8
0.0.7 9 / 8
0.0.6 9 / 8
0.0.5 9 / 8
0.0.4 9 / 8
0.0.3 9 / 8
0.0.2 9 / 7
0.0.1 9 / 7

v0.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.