@utoo/pack
> 🌖 High-performance bundler core for the Utoo toolchain, powered by [Turbopack](https://turbo.build/pack).
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@babel/code-frame | AI (phantom-deps): Framework-scoped convention dependency. | ai | |
| provenance | publisher-changed | AI (provenance): Change is manual->CI/CD with SLSA attestation, an improvement not a compromise indicator. | ai | |
| phantom-deps | phantom-dep:send | AI (phantom-deps): Used via config/runtime, standard for napi/bundler tooling. | ai | |
| phantom-deps | phantom-dep:@swc/helpers | AI (phantom-deps): Known implicit runtime dependency. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Prior spam flag was tied to human publisher elrrrrrrr; this version is CI-attested via GitHub Actions with provenance. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Usage is in NAPI binding detection code (which ldd to detect musl); standard pattern for native binary selection, not malicious. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): execSync('which ldd') is a standard musl detection pattern in NAPI bindings; benign and expected for this package type. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in readWebpackConfig.js loads user-provided config files; standard and expected behavior for a bundler/build tool. | ai |
Versions (showing 21 of 121)
| Version | Deps | Published |
|---|---|---|
| 1.2.8-alpha.2 | 10 / 9 | |
| 1.2.8-alpha.1 | 10 / 9 | |
| 1.2.8-alpha.0 | 10 / 9 | |
| 1.2.7-rc.1 | 10 / 9 | |
| 1.2.6-rc.2 | 10 / 9 | |
| 1.2.6-rc.1 | 10 / 9 | |
| 1.2.5-alpha.0 | 10 / 9 | |
| 1.2.0-rc.1 | 10 / 9 | |
| 1.2.0-alpha.1 | 10 / 9 | |
| 1.1.26-alpha.0 | 10 / 9 | |
| 1.1.25-alpha.2 | 10 / 9 | |
| 1.1.25-alpha.1 | 10 / 9 | |
| 1.1.25-alpha.0 | 10 / 9 | |
| 1.1.23-rc.1 | 10 / 9 | |
| 1.1.21-rc.2 | 10 / 9 | |
| 1.1.21-rc.1 | 10 / 9 | |
| 1.1.20-rc.1 | 10 / 9 | |
| 1.1.20-alpha.1 | 10 / 9 | |
| 1.1.20-alpha.0 | 10 / 9 | |
| 1.1.16-alpha.0 | 10 / 9 | |
| 1.1.14-alpha.0 | 10 / 9 |
v1.2.8-alpha.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.8-alpha.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (elrrrrrrr) than the most recent previously approved version (xusd320) on 2026-02-24, but elrrrrrrr is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.8-alpha.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.7-rc.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6-rc.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6-rc.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xusd320) than the most recent previously approved version (elrrrrrrr) on 2026-02-05, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.5-alpha.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0-rc.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0-alpha.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.26-alpha.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.25-alpha.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.25-alpha.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.25-alpha.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.23-rc.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.21-rc.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.21-rc.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.20-rc.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.20-alpha.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.20-alpha.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.16-alpha.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.14-alpha.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.