@weapp-vite/miniprogram-automator
11
Versions
—
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
No source commit
Maintainers
icebreaker
Keywords
weappwechatminiprogramautomatordevtoolsheadless
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/launch-CDd9gHVW.mjs | AI (source-diff): Bundled build output with readable source regions; not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/launch-F4arniwI.mjs | AI (source-diff): File is readable bundled ESM output, not obfuscated; long lines are from bundled source regions. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): 0.0.0 is the initial placeholder release in a monorepo; publisher has clean track record and legitimate repo. | ai | |
| source-diff | obfuscated-file:dist/launch-Didv0lMX.mjs | AI (source-diff): File is rollup-bundled ESM with readable identifiers and region comments; not obfuscated. Pattern is stable for this build tooling package. | ai | |
| source-diff | obfuscated-file:dist/launch-Bd3TZy1I.mjs | AI (source-diff): Large bundled ESM output from tsdown; readable source regions visible, not actual obfuscation. | ai | |
| provenance | slsa-provenance | AI (provenance): Package is published via CI with Sigstore SLSA attestation; stable positive signal for this package. | ai |