bower-json
Read bower.json files with semantics, normalisation, defaults and validation
11
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
desandropaulirishsatazorsheerunsindresorhuswibblymat
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from sindresorhus to desandro occurred in 2015 as a legitimate Bower project maintainer transition. Both are well-known npm contributors; no compromise indicators. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): desandro is a well-established npm publisher (174 approved packages, first seen 4075 days ago). Maintainer addition in 2015 reflects a legitimate Bower project handoff. | ai | |
| provenance | missing-githead | AI (provenance): Established package with clean diff and trusted publisher; missing gitHead is a minor provenance gap, not a security signal for this package. | ai | |
| provenance | no-provenance | AI (provenance): Lack of Sigstore attestation is a best-practice gap, not a security risk for this well-established, trusted package. | ai |