@vertz/native-compiler
Native Rust compiler for Vertz (signal transforms, JSX, CSS)
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): Standard NAPI platform-selection postinstall pattern; consistent with native Rust binding structure. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Platform-specific .node binaries are the expected artifact for a native Rust/NAPI compiler binding with SLSA provenance. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.2.80 | 0 / 1 | |
| 0.2.78 | 0 / 1 | |
| 0.2.76 | 0 / 1 | |
| 0.2.75 | 0 / 1 | |
| 0.2.74 | 0 / 1 | |
| 0.2.73 | 0 / 1 | |
| 0.2.71 | 0 / 1 | |
| 0.2.70 | 0 / 1 | |
| 0.2.68 | 0 / 1 | |
| 0.2.67 | 0 / 1 |
v0.2.80
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.78
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.76
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.75
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.74
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.73
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.71
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.70
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.68
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.67
3 findingsScript: node postinstall.cjs
Package contains compiled binaries that could be backdoors: • vertz-compiler.linux-x64.node
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.