@uxf/scripts
[](https://www.npmjs.com/package/@uxf/scripts) [](https://www.npmjs.com/package/@uxf/scripts) [ relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): CLI toolbox package; child_process use is inherent to its purpose (running audit/build/release commands). | ai |
Versions (showing 50 of 50)
| Version | Deps | Published |
|---|---|---|
| 11.119.0 | 10 / 6 | |
| 11.118.2 | 10 / 6 | |
| 11.118.0 | 10 / 6 | |
| 11.117.2 | 10 / 6 | |
| 11.115.0 | 10 / 6 | |
| 11.114.1 | 10 / 6 | |
| 11.114.0 | 9 / 5 | |
| 11.113.0 | 9 / 5 | |
| 11.112.1 | 9 / 5 | |
| 11.112.0 | 9 / 5 | |
| 11.111.2 | 9 / 5 | |
| 11.111.1 | 9 / 5 | |
| 11.111.0 | 9 / 5 | |
| 11.110.1 | 9 / 5 | |
| 11.110.0 | 9 / 5 | |
| 11.109.2 | 9 / 5 | |
| 11.109.1 | 9 / 5 | |
| 11.109.0 | 9 / 5 | |
| 11.108.0 | 9 / 5 | |
| 11.107.0 | 9 / 5 | |
| 11.105.0 | 9 / 1 | |
| 11.103.1 | 9 / 1 | |
| 11.99.0 | 9 / 1 | |
| 11.93.0 | 9 / 1 | |
| 11.90.0 | 9 / 1 | |
| 11.88.0 | 9 / 1 | |
| 11.86.0 | 9 / 1 | |
| 11.85.0 | 9 / 1 | |
| 11.83.0 | 9 / 0 | |
| 11.80.4 | 9 / 0 | |
| 11.80.0 | 9 / 0 | |
| 11.78.0 | 9 / 0 | |
| 11.77.1 | 9 / 0 | |
| 11.77.0 | 9 / 0 | |
| 11.76.0 | 9 / 0 | |
| 11.74.5 | 9 / 0 | |
| 11.74.4 | 9 / 0 | |
| 11.74.0 | 9 / 0 | |
| 11.72.3 | 9 / 0 | |
| 11.69.2 | 9 / 0 | |
| 11.69.1 | 9 / 0 | |
| 11.69.0 | 9 / 0 | |
| 11.67.1 | 8 / 0 | |
| 11.64.2 | 8 / 0 | |
| 11.64.1 | 8 / 0 | |
| 11.64.0 | 7 / 0 | |
| 11.63.0 | 7 / 0 | |
| 11.62.3 | 7 / 0 | |
| 11.62.2 | 7 / 0 | |
| 11.62.1 | 7 / 0 |
v11.119.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.118.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.118.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.117.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.115.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.114.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.114.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.113.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.112.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.112.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.111.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.111.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.111.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.110.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.109.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.109.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.109.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.108.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.107.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.105.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.103.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.99.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.93.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.90.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.88.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.86.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.85.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.83.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.80.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.80.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.78.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.77.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.77.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.76.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.74.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.74.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.74.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.72.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.69.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.69.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.69.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.67.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.64.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.64.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.63.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.62.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.62.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.62.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.