← Home

@tarojs/helper

31
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

yuchexuanzebindefaultleedrchankyjoqq592743779advancedcatbaosiqingzakaryliuzejiavasily.cjjhardenzheng2

Keywords

taro

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): SWC wasm plugins are documented compiler artifacts for this build tool, not backdoors. ai
maintainer-change maintainer-added AI (maintainer-change): Consistent with active large OSS org maintainer rotation. ai
typosquat typosquat.levenshtein:helmet AI (typosquat): Scoped package @tarojs/helper is part of the established Taro framework; no resemblance to helmet. ai
phantom-deps phantom-dep:@babel/parser AI (phantom-deps): Framework-scoped Babel dep; loaded by convention in Taro toolchain. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped Babel dep; loaded by convention in Taro toolchain. ai
phantom-deps phantom-dep:@babel/traverse AI (phantom-deps): Framework-scoped Babel dep; loaded by convention in Taro toolchain. ai

Versions (showing 31 of 31)

Version Deps Published
4.2.1 21 / 4
4.2.0 21 / 4
4.1.11 21 / 4
4.1.10 21 / 4
4.1.9 21 / 4
4.1.8 21 / 4
4.1.7 21 / 4
4.1.6 21 / 4
4.1.5 21 / 4
4.1.4 21 / 4
4.1.3 21 / 4
4.1.2 21 / 4
4.1.1 21 / 4
4.1.0 21 / 4
4.0.13 21 / 4
4.0.12 21 / 4
4.0.11 21 / 4
4.0.10 21 / 4
4.0.9 21 / 4
4.0.8 21 / 4
4.0.7 21 / 4
4.0.6 21 / 4
4.0.5 21 / 4
4.0.4 21 / 4
4.0.3 21 / 4
4.0.2 21 / 4
4.0.1 27 / 6
4.0.0 21 / 4
3.6.40 27 / 6
3.6.39 27 / 6
3.5.4 22 / 0

v4.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.12

2 findings
HIGH Bundled binary files (3) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode_pre_process.wasm • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.11

2 findings
HIGH Bundled binary files (3) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode_pre_process.wasm • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.10

2 findings
HIGH Bundled binary files (3) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode_pre_process.wasm • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.9

2 findings
HIGH Bundled binary files (3) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode_pre_process.wasm • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.8

2 findings
HIGH Bundled binary files (3) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode_pre_process.wasm • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.7

2 findings
HIGH Bundled binary files (3) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode_pre_process.wasm • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.6

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.5

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.3

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.2

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • swc/swc_plugin_compile_mode.wasm • swc/swc_plugin_define_config.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.