@wyw-in-js/transform
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:types/eval/broker.js | AI (source-diff): Type declaration mirror of broker.js; same legitimate pattern. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Passes env to spawned eval runner subprocess; standard child_process pattern. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version rewrite from Babel to oxc; large diff expected. | ai | |
| source-diff | net-exec-file:esm/eval/broker.js | AI (source-diff): Broker spawns eval runner subprocess — core architecture of CSS-in-JS transform tool. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() deserializes pre-evaluated CSS expressions; core to wyw-in-js transform pipeline. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used for safe exports property access with Object.prototype fallback; not obfuscation. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Module resolver loading Node builtins by name; expected pattern for a Babel/CSS-in-JS transform tool. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 2.3.0 | 12 / 11 | |
| 2.2.0 | 12 / 11 | |
| 2.1.6 | 12 / 11 | |
| 2.1.5 | 12 / 11 | |
| 2.1.4 | 12 / 11 | |
| 2.1.3 | 12 / 11 | |
| 2.1.2 | 12 / 11 | |
| 2.1.1 | 12 / 11 | |
| 2.1.0 | 12 / 11 | |
| 2.0.2 | 12 / 11 | |
| 2.0.1 | 12 / 11 | |
| 2.0.0 | 12 / 11 | |
| 1.1.0 | 15 / 21 | |
| 1.0.8 | 15 / 21 | |
| 1.0.7 | 15 / 21 | |
| 1.0.6 | 15 / 21 | |
| 1.0.5 | 15 / 21 | |
| 1.0.4 | 14 / 21 | |
| 1.0.3 | 14 / 21 | |
| 1.0.2 | 14 / 21 | |
| 1.0.1 | 14 / 21 | |
| 1.0.0 | 14 / 21 | |
| 0.8.1 | 15 / 22 | |
| 0.8.0 | 15 / 22 |
v2.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.