buffer-equal
return whether two buffers are equal
5
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
substackljharb
Keywords
bufferequal
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): substack commonly published early utility packages at 0.0.0; this package is 14 years old with 4.2M weekly downloads — clearly not a throwaway malicious package. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance on npm by many years; absence of provenance is expected and not a risk signal for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Legitimate transfer from substack to ljharb (Jordan Harband), a well-known trusted npm maintainer who maintains many packages under inspect-js org. This is a documented stewardship transition. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): ljharb is a well-known, trusted npm maintainer with a strong track record. Addition reflects legitimate stewardship of substack's packages. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by maintainer transition to ljharb is a known pattern for substack package stewardship transfers, not an account takeover indicator. | ai |