@vxrn/compiler
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:react-native-css-interop | AI (dependencies): react-native-css-interop is a legitimate React Native CSS interop library; stable dependency for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established publisher with long track record; no provenance is consistent across all versions of this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-private-methods | AI (phantom-deps): Babel plugins declared as deps and loaded by convention in compiler tooling; stable false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package; missing metadata is structural, not indicative of spam or malice. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all versions of this monorepo package; not a malice signal. | ai | |
| phantom-deps | phantom-dep:babel-plugin-react-compiler | AI (phantom-deps): Babel plugin loaded by convention in compiler tooling, not directly imported. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-react-jsx | AI (phantom-deps): Framework-scoped babel plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-regenerator | AI (phantom-deps): Framework-scoped babel plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:@react-native/babel-plugin-codegen | AI (phantom-deps): Platform-specific babel plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-destructuring | AI (phantom-deps): Framework-scoped babel plugin loaded by convention. | ai |
Versions (showing 99 of 399)
| Version | Deps | Published |
|---|---|---|
| 1.1.495 | 12 / 4 | |
| 1.1.494 | 12 / 4 | |
| 1.1.493 | 12 / 4 | |
| 1.1.492 | 12 / 4 | |
| 1.1.491 | 12 / 4 | |
| 1.1.490 | 12 / 4 | |
| 1.1.489 | 12 / 4 | |
| 1.1.488 | 12 / 4 | |
| 1.1.487 | 12 / 4 | |
| 1.1.486 | 12 / 4 | |
| 1.1.485 | 12 / 4 | |
| 1.1.484 | 12 / 4 | |
| 1.1.483 | 12 / 4 | |
| 1.1.482 | 12 / 4 | |
| 1.1.481 | 12 / 4 | |
| 1.1.480 | 12 / 4 | |
| 1.1.479 | 12 / 4 | |
| 1.1.478 | 12 / 4 | |
| 1.1.477 | 12 / 4 | |
| 1.1.476 | 12 / 4 | |
| 1.1.475 | 12 / 4 | |
| 1.1.474 | 12 / 4 | |
| 1.1.473 | 12 / 4 | |
| 1.1.472 | 12 / 4 | |
| 1.1.471 | 12 / 4 | |
| 1.1.470 | 12 / 4 | |
| 1.1.469 | 12 / 4 | |
| 1.1.468 | 12 / 4 | |
| 1.1.467 | 12 / 4 | |
| 1.1.466 | 12 / 4 | |
| 1.1.465 | 12 / 4 | |
| 1.1.464 | 12 / 4 | |
| 1.1.463 | 12 / 4 | |
| 1.1.462 | 12 / 4 | |
| 1.1.461 | 12 / 4 | |
| 1.1.460 | 12 / 4 | |
| 1.1.459 | 12 / 4 | |
| 1.1.458 | 12 / 4 | |
| 1.1.457 | 12 / 4 | |
| 1.1.456 | 12 / 4 | |
| 1.1.455 | 12 / 4 | |
| 1.1.454 | 12 / 4 | |
| 1.1.453 | 12 / 4 | |
| 1.1.452 | 12 / 4 | |
| 1.1.451 | 12 / 4 | |
| 1.1.450 | 12 / 4 | |
| 1.1.449 | 12 / 4 | |
| 1.1.448 | 12 / 4 | |
| 1.1.447 | 12 / 4 | |
| 1.1.446 | 12 / 4 | |
| 1.1.445 | 12 / 4 | |
| 1.1.444 | 12 / 4 | |
| 1.1.443 | 12 / 4 | |
| 1.1.442 | 12 / 4 | |
| 1.1.441 | 12 / 4 | |
| 1.1.440 | 12 / 4 | |
| 1.1.439 | 12 / 4 | |
| 1.1.438 | 12 / 4 | |
| 1.1.437 | 12 / 4 | |
| 1.1.436 | 12 / 4 | |
| 1.1.435 | 12 / 4 | |
| 1.1.434 | 12 / 4 | |
| 1.1.433 | 12 / 4 | |
| 1.1.432 | 12 / 4 | |
| 1.1.431 | 12 / 4 | |
| 1.1.430 | 12 / 4 | |
| 1.1.429 | 12 / 4 | |
| 1.1.428 | 12 / 4 | |
| 1.1.427 | 12 / 4 | |
| 1.1.426 | 12 / 4 | |
| 1.1.425 | 12 / 4 | |
| 1.1.424 | 12 / 4 | |
| 1.1.423 | 12 / 4 | |
| 1.1.422 | 12 / 4 | |
| 1.1.421 | 12 / 4 | |
| 1.1.420 | 12 / 4 | |
| 1.1.419 | 12 / 4 | |
| 1.1.418 | 12 / 4 | |
| 1.1.417 | 12 / 4 | |
| 1.1.416 | 12 / 4 | |
| 1.1.415 | 12 / 4 | |
| 1.1.414 | 12 / 4 | |
| 1.1.413 | 12 / 4 | |
| 1.1.412 | 12 / 4 | |
| 1.1.411 | 12 / 4 | |
| 1.1.410 | 12 / 4 | |
| 1.1.409 | 12 / 4 | |
| 1.1.408 | 12 / 4 | |
| 1.1.407 | 12 / 4 | |
| 1.1.406 | 12 / 4 | |
| 1.1.405 | 12 / 4 | |
| 1.1.404 | 12 / 4 | |
| 1.1.403 | 12 / 4 | |
| 1.1.402 | 12 / 4 | |
| 1.1.401 | 12 / 4 | |
| 1.1.400 | 12 / 4 | |
| 1.1.399 | 12 / 4 | |
| 1.1.398 | 12 / 4 | |
| 1.1.397 | 11 / 3 |
v1.1.480
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.479
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.478
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.477
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.476
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.475
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.474
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.473
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.472
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.471
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.470
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.469
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.468
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.467
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.466
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.465
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.464
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.463
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.462
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.461
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.460
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.459
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.458
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.457
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.456
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.455
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.454
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.453
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.452
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.451
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.450
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.449
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.448
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.447
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.446
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.445
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.444
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.443
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.442
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.441
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.440
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.439
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.438
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.437
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.436
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.435
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.434
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.433
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.432
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.431
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.430
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.429
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.428
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.427
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.426
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.425
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.424
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.423
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.422
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.421
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.420
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.419
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.418
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.417
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.416
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.415
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.414
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.413
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.412
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.411
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.410
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.409
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.408
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.407
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.406
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.405
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.404
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.403
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.402
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.401
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.400
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.399
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.398
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.397
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.