@willbooster/wbfy
A tool for applying WillBooster's conventional configures to npm packages
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/index.js | AI (source-diff): Bundled/minified build output, not true obfuscation; no malicious behavior present. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Config-parsing lib used via config files, expected for this tool's function. | ai | |
| phantom-deps | phantom-dep:json5 | AI (phantom-deps): Config-parsing lib used via config files, expected for this tool's function. | ai | |
| dependencies | unvetted-dep:minimal-promise-pool | AI (dependencies): minimal-promise-pool is a small promise concurrency utility with no known advisories or malware signals; its use in this tooling package is benign. | ai | |
| phantom-deps | phantom-dep:@willbooster/shared-lib | AI (phantom-deps): Same-org package used in config/template files; wbfy is a configuration tool that references packages without directly importing them. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:lodash.clonedeep | AI (phantom-deps): Referenced in config files but not directly imported; consistent with wbfy's configuration template management role. | ai | |
| phantom-deps | phantom-dep:@willbooster/shared-lib-node | AI (phantom-deps): Same-org package used in config/template files; consistent with wbfy's role as a configuration management tool. | ai | |
| phantom-deps | phantom-dep:libsodium | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:smol-toml | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:simple-git | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:libsodium-wrappers | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:fastest-levenshtein | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:minimal-promise-pool | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:@octokit/core | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:deepmerge | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai | |
| phantom-deps | phantom-dep:fast-glob | AI (phantom-deps): wbfy is a config-management tool; deps referenced in config templates/files without direct import is expected behavior for this package type. | ai |
Versions (showing 100 of 224)
| Version | Deps | Published |
|---|---|---|
| 12.3.2 | 15 / 21 | |
| 12.3.1 | 15 / 21 | |
| 12.3.0 | 15 / 21 | |
| 12.2.2 | 15 / 21 | |
| 12.2.1 | 15 / 21 | |
| 12.2.0 | 15 / 21 | |
| 12.1.0 | 15 / 21 | |
| 12.0.3 | 15 / 21 | |
| 12.0.2 | 15 / 21 | |
| 12.0.1 | 15 / 21 | |
| 12.0.0 | 15 / 21 | |
| 11.3.0 | 15 / 21 | |
| 11.2.1 | 15 / 21 | |
| 11.2.0 | 15 / 21 | |
| 11.1.0 | 15 / 21 | |
| 11.0.0 | 15 / 21 | |
| 10.0.0 | 15 / 21 | |
| 9.4.1 | 15 / 21 | |
| 9.4.0 | 15 / 21 | |
| 9.3.0 | 15 / 21 | |
| 9.2.0 | 15 / 21 | |
| 9.1.0 | 15 / 21 | |
| 9.0.3 | 15 / 21 | |
| 9.0.2 | 15 / 21 | |
| 9.0.1 | 15 / 21 | |
| 9.0.0 | 15 / 21 | |
| 8.2.0 | 17 / 21 | |
| 8.1.0 | 17 / 21 | |
| 8.0.1 | 17 / 21 | |
| 8.0.0 | 17 / 21 | |
| 7.1.0 | 18 / 21 | |
| 7.0.0 | 18 / 21 | |
| 6.1.1 | 18 / 21 | |
| 6.1.0 | 18 / 21 | |
| 6.0.0 | 18 / 21 | |
| 5.1.3 | 18 / 21 | |
| 5.1.2 | 18 / 21 | |
| 5.1.1 | 18 / 21 | |
| 5.1.0 | 18 / 21 | |
| 5.0.2 | 18 / 21 | |
| 5.0.1 | 17 / 20 | |
| 5.0.0 | 17 / 20 | |
| 4.3.10 | 17 / 20 | |
| 4.3.9 | 17 / 20 | |
| 4.3.8 | 17 / 20 | |
| 4.3.7 | 17 / 20 | |
| 4.3.6 | 17 / 20 | |
| 4.3.5 | 17 / 20 | |
| 4.3.4 | 17 / 20 | |
| 4.3.3 | 17 / 20 | |
| 4.3.2 | 17 / 20 | |
| 4.3.1 | 17 / 20 | |
| 4.3.0 | 17 / 20 | |
| 4.2.2 | 17 / 20 | |
| 4.2.1 | 17 / 20 | |
| 4.2.0 | 17 / 20 | |
| 4.1.0 | 17 / 20 | |
| 4.0.6 | 16 / 20 | |
| 4.0.5 | 16 / 20 | |
| 4.0.4 | 16 / 20 | |
| 4.0.3 | 16 / 20 | |
| 4.0.2 | 16 / 20 | |
| 4.0.1 | 16 / 20 | |
| 4.0.0 | 16 / 20 | |
| 3.1.0 | 16 / 20 | |
| 3.0.0 | 16 / 20 | |
| 2.1.0 | 16 / 18 | |
| 2.0.0 | 16 / 18 | |
| 1.15.6 | 16 / 19 | |
| 1.15.5 | 16 / 19 | |
| 1.15.4 | 15 / 19 | |
| 1.15.3 | 15 / 19 | |
| 1.15.2 | 15 / 19 | |
| 1.15.1 | 15 / 19 | |
| 1.15.0 | 15 / 19 | |
| 1.14.0 | 15 / 19 | |
| 1.13.0 | 15 / 19 | |
| 1.12.5 | 15 / 19 | |
| 1.12.4 | 15 / 19 | |
| 1.12.3 | 15 / 19 | |
| 1.12.2 | 15 / 19 | |
| 1.12.1 | 15 / 19 | |
| 1.12.0 | 15 / 19 | |
| 1.11.1 | 15 / 19 | |
| 1.11.0 | 15 / 20 | |
| 1.10.1 | 15 / 20 | |
| 1.10.0 | 15 / 20 | |
| 1.9.29 | 15 / 20 | |
| 1.9.28 | 15 / 20 | |
| 1.9.27 | 15 / 20 | |
| 1.9.26 | 15 / 20 | |
| 1.9.25 | 15 / 20 | |
| 1.9.24 | 15 / 20 | |
| 1.9.23 | 15 / 20 | |
| 1.9.22 | 15 / 20 | |
| 1.9.21 | 15 / 20 | |
| 1.9.20 | 15 / 20 | |
| 1.9.19 | 15 / 20 | |
| 1.9.18 | 15 / 20 | |
| 1.9.17 | 15 / 20 |
v12.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v10.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.6
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.5
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.4
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.12.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.12.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.12.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.12.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.12.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.11.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.