@tscircuit/eval
Evaluate code in a full tscircuit runtime environment, including Sucrase transpilation and execution, so you just need to send the code to be executed with automatic handling of imports from `@tsci/*`
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:@tsci/tscircuit.ti | AI (npm-metadata): devDependency, SHA-pinned github ref; build-time only, consistent with prior approved versions. | ai | |
| npm-metadata | url-dep:@tscircuit/breakout-point-solver | AI (npm-metadata): devDependency github ref, not shipped in published package. | ai | |
| npm-metadata | url-dep:@tscircuit/jlcpcb-manufacturing-specs | AI (npm-metadata): SHA-pinned devDependency only; not shipped to consumers, and SHA pinning is actually more secure than semver. | ai | |
| source-diff | encoded-string-file:dist/webworker/entrypoint.js | AI (source-diff): Minified bundled SVG/chart code in webworker entrypoint; not an obfuscated payload, stable pattern for this package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs a local version-copy script and bun install --ignore-scripts; no external fetch or malicious behavior. | ai | |
| source-diff | encoded-string-file:dist/blob-url.js | AI (source-diff): dist/blob-url.js is intentionally built by build:blob-url script to embed a Web Worker as a base64 blob URL. The encoded content is standard ESM bundler boilerplate, not a malicious payload. Stable pattern for this package. | ai |
Versions (showing 51 of 996)
| Version | Deps | Published |
|---|---|---|
| 0.0.1079 | 0 / 78 | |
| 0.0.1078 | 0 / 78 | |
| 0.0.1077 | 0 / 78 | |
| 0.0.1076 | 0 / 78 | |
| 0.0.1075 | 0 / 78 | |
| 0.0.1074 | 0 / 78 | |
| 0.0.1073 | 0 / 78 | |
| 0.0.1072 | 0 / 78 | |
| 0.0.1071 | 0 / 78 | |
| 0.0.1070 | 0 / 78 | |
| 0.0.1069 | 0 / 78 | |
| 0.0.1068 | 0 / 78 | |
| 0.0.1067 | 0 / 78 | |
| 0.0.1066 | 0 / 78 | |
| 0.0.1065 | 0 / 78 | |
| 0.0.1064 | 0 / 78 | |
| 0.0.1063 | 0 / 78 | |
| 0.0.1062 | 0 / 78 | |
| 0.0.1061 | 0 / 78 | |
| 0.0.1060 | 0 / 78 | |
| 0.0.1059 | 0 / 78 | |
| 0.0.1058 | 0 / 78 | |
| 0.0.1057 | 0 / 78 | |
| 0.0.1056 | 0 / 78 | |
| 0.0.1055 | 0 / 78 | |
| 0.0.1054 | 0 / 78 | |
| 0.0.1053 | 0 / 78 | |
| 0.0.1052 | 0 / 78 | |
| 0.0.1051 | 0 / 78 | |
| 0.0.1050 | 0 / 77 | |
| 0.0.1049 | 0 / 77 | |
| 0.0.1048 | 0 / 77 | |
| 0.0.1047 | 0 / 77 | |
| 0.0.1046 | 0 / 77 | |
| 0.0.1045 | 0 / 77 | |
| 0.0.1044 | 0 / 77 | |
| 0.0.1043 | 0 / 77 | |
| 0.0.1042 | 0 / 77 | |
| 0.0.1041 | 0 / 77 | |
| 0.0.1040 | 0 / 77 | |
| 0.0.1039 | 0 / 77 | |
| 0.0.1038 | 0 / 77 | |
| 0.0.1037 | 0 / 77 | |
| 0.0.1036 | 0 / 77 | |
| 0.0.1035 | 0 / 77 | |
| 0.0.1034 | 0 / 77 | |
| 0.0.1033 | 0 / 77 | |
| 0.0.1032 | 0 / 77 | |
| 0.0.1031 | 0 / 76 | |
| 0.0.1030 | 0 / 76 | |
| 0.0.1029 | 0 / 76 |
v0.0.1079
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1078
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1077
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1076
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1075
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1074
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1073
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1072
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1071
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1070
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1069
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1068
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1067
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1066
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1065
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1064
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1063
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1062
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1061
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1060
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1059
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1058
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1057
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1056
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1055
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1054
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1053
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1052
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1051
2 findingsDependency '@tsci/tscircuit.ti' in `devDependencies` points to 'github:tscircuit/ti#57e314be4b2b06bc546d4def7453e619604d1157' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1050
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1049
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1048
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1047
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1046
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1045
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1044
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1043
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1042
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1041
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1040
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1039
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1038
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1037
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1036
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1035
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1034
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1033
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1032
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1031
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1030
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1029
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.