@wterm/core
Headless terminal emulator core for the web — WASM bridge and WebSocket transport
13
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
ctate
Keywords
terminalemulatorwasmzigxterm
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA attestation present; gitHead absence is a minor metadata gap, not a supply-chain risk for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is confirmed legitimate by SLSA/Sigstore attestation on the same release. | ai | |
| source-diff | obfuscated-file:dist/wasm-inline.js | AI (source-diff): File contains a base64-encoded WebAssembly binary (starts with AGFzbQ = WASM magic bytes). Long lines are inherent to base64 encoding, not obfuscation. Regenerated by scripts/inline-wasm.js prebuild step. | ai | |
| source-diff | obfuscated-file:dist/wasm-inline.d.ts | AI (source-diff): TypeScript declaration file for the WASM base64 constant. Long line is the literal base64 WASM value in the type declaration — not obfuscation. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is fully explained by the addition of the inlined WASM binary as base64 in wasm-inline.js. Expected for this package type. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @wterm/core is a scoped terminal emulator package; 'core' vs 'cors' similarity is coincidental and not an impersonation attempt. Stable false positive for this package. | ai |