@swc/wasm
wasm module for swc
51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
kdy1
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): wasm_bg.wasm is the package's core compiled artifact for a wasm module; expected every version. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): The require(String.raw`util`) pattern is a static wasm-bindgen generated call to Node's built-in 'util' module. Not dynamic in any meaningful sense; stable false positive for this package. | ai | |
| license | uncommon-license:Apache-2.0/MIT | AI (license): Apache-2.0/MIT dual licensing is the standard license for the SWC project; permissive and well-understood. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): This is standard wasm-bindgen generated glue code for exposing WASM function creation to JS. Expected and stable across all versions of this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() usage is standard wasm-bindgen generated glue code for property access bridging. Not obfuscation; expected in all versions of this package. | ai | |
| provenance | no-provenance | AI (provenance): Established SWC ecosystem package; lack of Sigstore provenance is common and not a risk signal for this well-known publisher. | ai |
Versions (showing 51 of 458)
| Version | Deps | Published |
|---|---|---|
| 1.15.46 | 0 / 0 | |
| 1.15.43 | 0 / 0 | |
| 1.15.41 | 0 / 0 | |
| 1.15.40 | 0 / 0 | |
| 1.15.33 | 0 / 0 | |
| 1.15.32 | 0 / 0 | |
| 1.15.30 | 0 / 0 | |
| 1.15.26 | 0 / 0 | |
| 1.15.24 | 0 / 0 | |
| 1.15.21 | 0 / 0 | |
| 1.15.18 | 0 / 0 | |
| 1.15.17 | 0 / 0 | |
| 1.15.13 | 0 / 0 | |
| 1.15.11 | 0 / 0 | |
| 1.15.10 | 0 / 0 | |
| 1.15.8 | 0 / 0 | |
| 1.15.7 | 0 / 0 | |
| 1.15.6 | 0 / 0 | |
| 1.15.5 | 0 / 0 | |
| 1.15.4 | 0 / 0 | |
| 1.15.3 | 0 / 0 | |
| 1.15.2 | 0 / 0 | |
| 1.15.1 | 0 / 0 | |
| 1.15.0 | 0 / 0 | |
| 1.14.0 | 0 / 0 | |
| 1.13.21 | 0 / 0 | |
| 1.13.20 | 0 / 0 | |
| 1.13.19 | 0 / 0 | |
| 1.13.5 | 0 / 0 | |
| 1.13.4 | 0 / 0 | |
| 1.13.3 | 0 / 0 | |
| 1.13.2 | 0 / 0 | |
| 1.13.1 | 0 / 0 | |
| 1.13.0 | 0 / 0 | |
| 1.12.14 | 0 / 0 | |
| 1.12.11 | 0 / 0 | |
| 1.12.9 | 0 / 0 | |
| 1.12.7 | 0 / 0 | |
| 1.12.6 | 0 / 0 | |
| 1.12.5 | 0 / 0 | |
| 1.12.4 | 0 / 0 | |
| 1.12.3 | 0 / 0 | |
| 1.12.2 | 0 / 0 | |
| 1.12.1 | 0 / 0 | |
| 1.12.0 | 0 / 0 | |
| 1.11.31 | 0 / 0 | |
| 1.11.29 | 0 / 0 | |
| 1.11.24 | 0 / 0 | |
| 1.11.22 | 0 / 0 | |
| 1.11.21 | 0 / 0 | |
| 1.11.20 | 0 / 0 |
v1.15.46
2 findings
HIGH
Bundled binary files (1)
npm-metadata
Package contains compiled binaries that could be backdoors: • wasm_bg.wasm
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.