← Home

@usebruno/js

29
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

anoopmd

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:crypto-js-3.1.9-1 AI (dependencies): Legacy crypto-js version alias kept for backward-compat sandbox scripts, established pattern. ai
source-diff source-size-tripled AI (source-diff): Growth is a bundled rollup sandbox library (chai/moment), not injected code. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is a well-established templating library; ^4.7.9 is the patched range addressing known XSS/prototype-pollution issues. ai
dependencies unvetted-dep:@usebruno/crypto-js AI (dependencies): Bruno-org maintained fork of crypto-js; consistent across all @usebruno/* package versions. ai
provenance no-provenance AI (provenance): Established Bruno ecosystem package; lack of provenance is consistent across all versions. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Same — scoped Bruno package, not a typosquat of ajv. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Appears in a test spec verifying sandbox blocks /etc/passwd access — not production credential harvesting. ai
semgrep semgrep:dynamic-require AI (semgrep): Part of the CJS loader in a sandboxed VM environment; dynamic require is the core feature being implemented. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used in a sandboxed expression evaluator — expected pattern for this type of JS runtime utility. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires inside bundled chai library code, not package-authored logic. ai
typosquat typosquat.levenshtein:qs AI (typosquat): @usebruno/js is a scoped package for the Bruno API tool, not a typosquat of qs. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): ajv is a declared dependency used indirectly via config/schema validation; stable false positive for this package. ai
phantom-deps phantom-dep:xml2js AI (phantom-deps): Declared dependency exposed to sandbox users; indirect usage is expected. ai
phantom-deps phantom-dep:cheerio AI (phantom-deps): Declared dependency exposed to sandbox users; indirect usage is expected. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Declared dependency exposed to sandbox users; indirect usage is expected. ai
phantom-deps phantom-dep:ajv-formats AI (phantom-deps): Companion to ajv; indirect usage via config is expected. ai
semgrep semgrep:base64-decode AI (semgrep): Fires on a bundled moment.js version string line, not actual base64 decode logic. ai
typosquat typosquat.levenshtein:jest AI (typosquat): Same — scoped Bruno package, not a typosquat of jest. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Same — scoped Bruno package, not a typosquat of pg. ai
typosquat typosquat.levenshtein:rxjs AI (typosquat): Same — scoped Bruno package, not a typosquat of rxjs. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Same — scoped Bruno package, not a typosquat of joi. ai

Versions (showing 29 of 29)

Version Deps Published
0.48.0 25 / 5
0.47.0 25 / 4
0.45.1 23 / 4
0.45.0 23 / 4
0.43.0 24 / 4
0.42.2 24 / 4
0.42.1 24 / 4
0.42.0 24 / 4
0.41.0 24 / 4
0.40.0 22 / 4
0.39.0 22 / 4
0.38.0 23 / 4
0.37.0 23 / 4
0.36.0 23 / 6
0.35.0 23 / 6
0.34.0 23 / 6
0.33.0 23 / 6
0.32.0 23 / 6
0.31.0 23 / 6
0.30.0 23 / 6
0.29.0 22 / 6
0.28.0 22 / 6
0.27.0 22 / 6
0.26.0 22 / 6
0.25.0 22 / 6
0.24.0 20 / 6
0.15.0 20 / 12
0.14.0 17 / 0
0.13.0 17 / 0

v0.29.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.