@xuda.io/xuda-worker-bundle
xuda framework
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Internal framework with 3678 versions and years of history; sparse metadata is a stable characteristic, not a spam signal. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() is inside a legacy evalJson() helper for JSON parsing — not a dynamic code execution attack vector in this context. | ai |
Versions (showing 51 of 859)
| Version | Deps | Published |
|---|---|---|
| 1.4.11 | 0 / 0 | |
| 1.4.10 | 0 / 0 | |
| 1.4.9 | 0 / 0 | |
| 1.4.8 | 0 / 0 | |
| 1.4.7 | 0 / 0 | |
| 1.3.2714 | 0 / 0 | |
| 1.3.2713 | 0 / 0 | |
| 1.3.2712 | 0 / 0 | |
| 1.3.2711 | 0 / 0 | |
| 1.3.2710 | 0 / 0 | |
| 1.3.2709 | 0 / 0 | |
| 1.3.2708 | 0 / 0 | |
| 1.3.2707 | 0 / 0 | |
| 1.3.2706 | 0 / 0 | |
| 1.3.2705 | 0 / 0 | |
| 1.3.2704 | 0 / 0 | |
| 1.3.2703 | 0 / 0 | |
| 1.3.2702 | 0 / 0 | |
| 1.3.2701 | 0 / 0 | |
| 1.3.2700 | 0 / 0 | |
| 1.3.2699 | 0 / 0 | |
| 1.3.2698 | 0 / 0 | |
| 1.3.2697 | 0 / 0 | |
| 1.3.2696 | 0 / 0 | |
| 1.3.2695 | 0 / 0 | |
| 1.3.2694 | 0 / 0 | |
| 1.3.2693 | 0 / 0 | |
| 1.3.2692 | 0 / 0 | |
| 1.3.2691 | 0 / 0 | |
| 1.3.2690 | 0 / 0 | |
| 1.3.2689 | 0 / 0 | |
| 1.3.2688 | 0 / 0 | |
| 1.3.2687 | 0 / 0 | |
| 1.3.2686 | 0 / 0 | |
| 1.3.2685 | 0 / 0 | |
| 1.3.2684 | 0 / 0 | |
| 1.3.2683 | 0 / 0 | |
| 1.3.2682 | 0 / 0 | |
| 1.3.2681 | 0 / 0 | |
| 1.3.2680 | 0 / 0 | |
| 1.3.2679 | 0 / 0 | |
| 1.3.2678 | 0 / 0 | |
| 1.3.2677 | 0 / 0 | |
| 1.3.2676 | 0 / 0 | |
| 1.3.2675 | 0 / 0 | |
| 1.3.2674 | 0 / 0 | |
| 1.3.2673 | 0 / 0 | |
| 1.3.2672 | 0 / 0 | |
| 1.3.2671 | 0 / 0 | |
| 1.3.2670 | 0 / 0 | |
| 1.3.2669 | 0 / 0 |
v1.4.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2714
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2713
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2712
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2711
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2710
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2709
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2708
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2707
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2706
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2705
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2704
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2703
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2702
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2701
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2700
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2699
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2698
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2697
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2696
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2695
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2694
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2693
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2692
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2691
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2690
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2689
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2688
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2687
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2686
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2685
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2684
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2683
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2682
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2681
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2680
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2679
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2678
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2677
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2676
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2675
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2674
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2673
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2672
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2671
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2670
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2669
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.