← Home

@vercel/python-analysis

20
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matheussmatt.strakavercel-release-botzeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): WASM build output from documented build:wasm pipeline, stable across versions. ai
provenance publisher-changed AI (provenance): Vercel migrated publishing from vercel-release-bot to GitHub Actions CI; SLSA attestation confirms legitimate CI/CD origin. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainer (matt.straka) consistent with Vercel org transition; package has SLSA provenance backing the release. ai
bogus-package bogus-package AI (bogus-package): Vercel monorepo packages consistently lack descriptions/keywords and share templated name shapes; this is a stable false positive for @vercel/* packages published by vercel-release-bot. ai
dependencies unvetted-dep:pip-requirements-js AI (dependencies): pip-requirements-js is contextually appropriate for a Python analysis package that needs to parse pip requirements files. Legitimate use case. ai
npm-metadata no-description AI (npm-metadata): Official Vercel monorepo package; missing description is a cosmetic issue, not a malware signal. Stable false positive for this package. ai
phantom-deps phantom-dep:@bytecodealliance/preview2-shim AI (phantom-deps): @bytecodealliance/preview2-shim is a WASM component model shim used via the imports map and build pipeline, not a direct JS import. This pattern is stable for this package. ai

Versions (showing 20 of 20)

Version Deps Published
0.12.0 7 / 6
0.11.1 7 / 6
0.11.0 7 / 6
0.10.1 7 / 6
0.10.0 7 / 6
0.9.1 8 / 6
0.9.0 8 / 6
0.8.2 8 / 6
0.8.1 8 / 6
0.8.0 8 / 6
0.7.0 8 / 6
0.6.0 8 / 6
0.5.0 8 / 6
0.4.1 8 / 6
0.4.0 8 / 6
0.3.2 8 / 6
0.3.1 8 / 6
0.3.0 8 / 6
0.2.0 7 / 5
0.1.1 7 / 6

v0.12.0

2 findings
HIGH Bundled binary files (3) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/wasm/vercel_python_analysis.core.wasm • dist/wasm/vercel_python_analysis.core2.wasm • dist/wasm/vercel_python_analysis.core3.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.