@zokugun/tsc-leda
CLI utility compiling (with `tsc`) and preparing TS projects for dual ESM/CJS distribution
11
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
daiyam
Keywords
cjscommonjsesmtsc
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher is GitHub Actions CI/CD with SLSA provenance attestation; this is the expected publish pattern for this package going forward. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs patch-package, a declared runtime dep; standard patching pattern, not arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:patch-package | AI (phantom-deps): patch-package is invoked via postinstall script, not imported directly; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:enquirer | AI (phantom-deps): enquirer is a CLI prompt library likely used at runtime via dynamic invocation; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@zokugun/log-update-plus | AI (phantom-deps): Same-org scoped dep; likely used transitively or indirectly — stable false positive for this package. | ai | |
| provenance | slsa-provenance | AI (provenance): Published via CI/CD with Sigstore SLSA attestation; stable supply chain signal for this package. | ai |