@utoo/pack
> 🌖 High-performance bundler core for the Utoo toolchain, powered by [Turbopack](https://turbo.build/pack).
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@babel/code-frame | AI (phantom-deps): Framework-scoped convention dependency. | ai | |
| provenance | publisher-changed | AI (provenance): Change is manual->CI/CD with SLSA attestation, an improvement not a compromise indicator. | ai | |
| phantom-deps | phantom-dep:send | AI (phantom-deps): Used via config/runtime, standard for napi/bundler tooling. | ai | |
| phantom-deps | phantom-dep:@swc/helpers | AI (phantom-deps): Known implicit runtime dependency. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Prior spam flag was tied to human publisher elrrrrrrr; this version is CI-attested via GitHub Actions with provenance. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Usage is in NAPI binding detection code (which ldd to detect musl); standard pattern for native binary selection, not malicious. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): execSync('which ldd') is a standard musl detection pattern in NAPI bindings; benign and expected for this package type. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in readWebpackConfig.js loads user-provided config files; standard and expected behavior for a bundler/build tool. | ai |
Versions (showing 51 of 64)
| Version | Deps | Published |
|---|---|---|
| 1.4.29 | 14 / 9 | |
| 1.4.28 | 14 / 9 | |
| 1.4.27 | 14 / 9 | |
| 1.4.26 | 14 / 9 | |
| 1.4.25 | 14 / 9 | |
| 1.4.24 | 14 / 9 | |
| 1.4.23 | 14 / 9 | |
| 1.4.22 | 14 / 9 | |
| 1.4.21 | 14 / 9 | |
| 1.4.20 | 14 / 9 | |
| 1.4.19 | 14 / 9 | |
| 1.4.18 | 14 / 9 | |
| 1.4.17 | 14 / 9 | |
| 1.4.16 | 14 / 9 | |
| 1.4.14 | 14 / 9 | |
| 1.4.13 | 14 / 9 | |
| 1.4.12 | 14 / 9 | |
| 1.4.11 | 14 / 9 | |
| 1.4.9 | 14 / 9 | |
| 1.4.8 | 14 / 9 | |
| 1.4.7 | 14 / 9 | |
| 1.4.6 | 14 / 9 | |
| 1.4.5 | 14 / 9 | |
| 1.4.4 | 14 / 9 | |
| 1.4.3 | 14 / 9 | |
| 1.4.2 | 14 / 9 | |
| 1.4.1 | 14 / 9 | |
| 1.4.0 | 14 / 9 | |
| 1.3.11 | 14 / 9 | |
| 1.3.10 | 14 / 9 | |
| 1.3.9 | 14 / 9 | |
| 1.3.8 | 14 / 9 | |
| 1.3.7 | 14 / 9 | |
| 1.3.6 | 14 / 9 | |
| 1.3.4 | 14 / 9 | |
| 1.3.3 | 14 / 9 | |
| 1.3.2 | 13 / 9 | |
| 1.3.1 | 14 / 9 | |
| 1.3.0 | 14 / 9 | |
| 1.2.13 | 10 / 9 | |
| 1.2.12 | 10 / 9 | |
| 1.2.11 | 10 / 9 | |
| 1.2.10 | 10 / 9 | |
| 1.2.9 | 10 / 9 | |
| 1.2.8 | 10 / 9 | |
| 1.2.7 | 10 / 9 | |
| 1.2.6 | 10 / 9 | |
| 1.2.5 | 10 / 9 | |
| 1.2.4 | 10 / 9 | |
| 1.1.25 | 10 / 9 | |
| 1.1.24 | 10 / 9 |
v1.4.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.20
3 findingsThis version was published by a different npm account than previous versions on 2026-07-07. This could indicate a legitimate maintainer transition or an account compromise.
[Reject — re-review on republish] (prior reject: AI (bogus-package): Publisher elrrrrrrr is SPAM-FLAGGED; this finding generalizes to all versions of this package.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: elrrrrrrr. • [S_NO_KEYWORDS] No keywords declared.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.19
3 findingsThis version was published by a different npm account than previous versions on 2026-07-06. This could indicate a legitimate maintainer transition or an account compromise.
[Reject — re-review on republish] (prior reject: AI (bogus-package): Publisher elrrrrrrr is SPAM-FLAGGED; this finding generalizes to all versions of this package.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: elrrrrrrr. • [S_NO_KEYWORDS] No keywords declared.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.18
3 findingsThis version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.
[Reject — re-review on republish] (prior reject: AI (bogus-package): Publisher elrrrrrrr is SPAM-FLAGGED; this finding generalizes to all versions of this package.) Matched 2 signal(s), weighted score 4: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: elrrrrrrr. • [S_NO_KEYWORDS] No keywords declared.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.8
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (elrrrrrrr) on 2026-05-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.4.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.