← Home

aontu

Unifier.

38
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

rjrodger

Keywords

unify

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@tabnas/directive AI (phantom-deps): Referenced via config/aliasify, not a real gap. ai
dependencies unvetted-dep:@tabnas/expr AI (dependencies): Same author's own package family replacing prior @jsonic/* deps. ai
dependencies unvetted-dep:@tabnas/path AI (dependencies): Same author's own package family replacing prior @jsonic/* deps. ai
dependencies unvetted-dep:@tabnas/debug AI (dependencies): Same author's own package family replacing prior @jsonic/* deps. ai
dependencies unvetted-dep:@tabnas/jsonic AI (dependencies): Same author's own package family replacing prior @jsonic/* deps. ai
dependencies unvetted-dep:@tabnas/directive AI (dependencies): Same author's own package family replacing prior @jsonic/* deps. ai
dependencies unvetted-dep:@tabnas/multisource AI (dependencies): Same author's own package family replacing prior @jsonic/* deps. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Match is in a comment documenting intended CLI behavior, not executed code. ai
phantom-deps phantom-dep:@jsonic/path AI (phantom-deps): Used indirectly via aliasify config; stable pattern for this package. ai
phantom-deps phantom-dep:@jsonic/directive AI (phantom-deps): Used indirectly via aliasify config; stable pattern for this package. ai
phantom-deps phantom-dep:@jsonic/multisource AI (phantom-deps): Used indirectly via aliasify config; stable pattern for this package. ai
phantom-deps phantom-dep:@jsonic/expr AI (phantom-deps): Used indirectly via aliasify config; stable pattern for this package. ai
phantom-deps phantom-dep:jsonic AI (phantom-deps): Used indirectly via aliasify config; stable pattern for this package. ai

Versions (showing 38 of 38)

Version Deps Published
0.48.1 6 / 3
0.48.0 6 / 3
0.46.0 5 / 3
0.45.1 5 / 3
0.44.0 4 / 3
0.43.0 4 / 3
0.42.0 4 / 3
0.41.0 5 / 3
0.40.0 5 / 3
0.39.0 5 / 4
0.38.0 5 / 4
0.37.1 5 / 4
0.37.0 5 / 4
0.36.0 5 / 4
0.35.2 5 / 4
0.35.0 5 / 4
0.34.5 5 / 4
0.34.4 5 / 4
0.34.1 5 / 4
0.33.2 5 / 4
0.33.0 5 / 4
0.32.1 5 / 4
0.31.0 5 / 4
0.30.2 5 / 4
0.30.1 5 / 4
0.29.0 5 / 12
0.28.0 5 / 12
0.27.0 5 / 12
0.26.0 5 / 12
0.25.3 5 / 12
0.25.2 5 / 12
0.25.1 5 / 12
0.25.0 5 / 12
0.24.0 5 / 12
0.23.0 5 / 12
0.22.0 5 / 12
0.21.1 5 / 12
0.20.0 5 / 12

v0.48.1

2 findings
HIGH etc-passwd-access: src/lang.ts:660 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux (matched inside a comment — likely documentation, not executed code) Source: https://github.com/rjrodger/aontu/blob/ce600c90d8baab49c345ffd02017b4cbf4664a4f/src/lang.ts#L660 658 | 659 | // SECURITY: the default resolver reads any file/package the process can > 660 | // reach — @"path" follows relative paths (`@"../../etc/passwd"`) and 661 | // symlinks with no containment check, and @"pkg" can require() arbitrary 662 | // installed modules. This is intentional for the CLI, but it means a

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.48.0

2 findings
HIGH etc-passwd-access: src/lang.ts:660 semgrep

Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux (matched inside a comment — likely documentation, not executed code) Source: https://github.com/rjrodger/aontu/blob/a374614be3b6c69bafe1b7410a44adf43533318b/src/lang.ts#L660 658 | 659 | // SECURITY: the default resolver reads any file/package the process can > 660 | // reach — @"path" follows relative paths (`@"../../etc/passwd"`) and 661 | // symlinks with no containment check, and @"pkg" can require() arbitrary 662 | // installed modules. This is intentional for the CLI, but it means a

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.