← Home

build-ts

[![Test](https://github.com/WillBooster/build-ts/actions/workflows/test.yml/badge.svg)](https://github.com/WillBooster/build-ts/actions/workflows/test.yml) [![semantic-release](https://img.shields.io/badge/%20%20%F0%9F%93%A6%F0%9F%9A%80-semantic--release-

51
Versions
UNLICENSED
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

exkazuu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publisher with SLSA attestation; provenance direction is IMPROVED. ai
phantom-deps phantom-dep:@babel/plugin-transform-runtime AI (phantom-deps): Babel plugin loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@rollup/plugin-node-resolve AI (phantom-deps): Rollup plugin loaded by convention in build tool config; stable false positive. ai
phantom-deps phantom-dep:rollup-plugin-node-externals AI (phantom-deps): Rollup plugin loaded by convention; stable false positive. ai
phantom-deps phantom-dep:babel-plugin-transform-remove-console AI (phantom-deps): Babel plugin loaded by convention; stable false positive. ai
phantom-deps phantom-dep:rollup-plugin-preserve-directives AI (phantom-deps): Rollup plugin loaded by convention; stable false positive. ai
dependencies unvetted-dep:@willbooster/shared-lib-node AI (dependencies): First-party WillBooster shared library; consistent with publisher identity. ai
dependencies unvetted-dep:@babel/plugin-proposal-explicit-resource-management AI (dependencies): Official @babel scoped package; consistent with build tool function. ai
dependencies unvetted-dep:rollup-plugin-string AI (dependencies): Legitimate rollup plugin consistent with build-ts function. ai
dependencies unvetted-dep:rollup-plugin-analyzer AI (dependencies): Legitimate rollup plugin consistent with build-ts function. ai
dependencies unvetted-dep:rollup-plugin-keep-import AI (dependencies): Legitimate rollup plugin consistent with build-ts function. ai
dependencies unvetted-dep:rollup-plugin-node-externals AI (dependencies): Legitimate rollup plugin consistent with build-ts function. ai
dependencies unvetted-dep:rollup-plugin-preserve-directives AI (dependencies): Legitimate rollup plugin consistent with build-ts function. ai
phantom-deps phantom-dep:oxc-parser AI (phantom-deps): Config-loaded parser dep; consistent with build tool pattern. ai
phantom-deps phantom-dep:magic-string AI (phantom-deps): Config-loaded dep; consistent with build tool pattern. ai
phantom-deps phantom-dep:@willbooster/shared-lib-node AI (phantom-deps): First-party dep loaded by convention; stable for this package. ai
phantom-deps phantom-dep:@typescript/native-preview AI (phantom-deps): Config-loaded dep; consistent with build tool pattern. ai
phantom-deps phantom-dep:babel-plugin-polyfill-corejs3 AI (phantom-deps): Framework-scoped babel plugin; consistent with build tool pattern. ai
phantom-deps phantom-dep:@babel/plugin-proposal-decorators AI (phantom-deps): Framework-scoped babel plugin; consistent with build tool pattern. ai
phantom-deps phantom-dep:@babel/plugin-syntax-import-attributes AI (phantom-deps): Framework-scoped babel plugin; consistent with build tool pattern. ai
phantom-deps phantom-dep:@babel/plugin-proposal-explicit-resource-management AI (phantom-deps): Framework-scoped babel plugin; consistent with build tool pattern. ai
phantom-deps phantom-dep:terser AI (phantom-deps): Config-loaded dep consistent with build tool pattern; stable for this package. ai
phantom-deps phantom-dep:rolldown AI (phantom-deps): Config-loaded bundler dep; coherent with rollup→rolldown migration. ai
phantom-deps phantom-dep:rollup-plugin-keep-import AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-replace AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:rollup-plugin-analyzer AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-commonjs AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:@rollup/pluginutils AI (phantom-deps): Rollup utility loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-babel AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:rollup-plugin-string AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Build tool; deps loaded by convention, not direct import. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): CLI tool; yargs used via bin entry, not direct import. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Known implicit polyfill dependency for babel/rollup builds. ai
phantom-deps phantom-dep:date-time AI (phantom-deps): Utility loaded by convention in build toolchain. ai
phantom-deps phantom-dep:pretty-ms AI (phantom-deps): Utility loaded by convention in build toolchain. ai
phantom-deps phantom-dep:signal-exit AI (phantom-deps): Runtime utility loaded by convention. ai
phantom-deps phantom-dep:core-js-pure AI (phantom-deps): Known implicit polyfill dependency for babel/rollup builds. ai
phantom-deps phantom-dep:rollup-plugin-ts AI (phantom-deps): Rollup plugin loaded by convention in build config. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Framework-scoped babel preset, loaded by convention. ai
phantom-deps phantom-dep:@babel/preset-react AI (phantom-deps): Framework-scoped babel preset, loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-json AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-terser AI (phantom-deps): Rollup plugin loaded by convention. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Framework-scoped babel preset, loaded by convention. ai
install-scripts install-script:postinstall AI (install-scripts): husky || true is a standard dev-tooling git-hooks setup; not a security risk. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): tsx used as CLI runner in scripts, not imported directly. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): TypeScript build tool; typescript loaded as a peer/runtime dep by convention. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): Build tool that wraps rollup; rollup is loaded by convention, not direct import. ai

Versions (showing 51 of 51)

Version Deps Published
20.0.0 14 / 18
19.0.0 14 / 18
18.0.0 14 / 17
17.3.1 17 / 17
17.3.0 17 / 17
17.2.0 17 / 17
17.1.37 17 / 17
17.1.36 17 / 17
17.1.35 17 / 17
17.1.34 17 / 17
17.1.33 16 / 18
17.1.32 16 / 18
17.1.31 17 / 17
17.1.30 21 / 19
17.1.29 22 / 19
17.1.28 33 / 22
17.1.27 33 / 22
17.1.26 33 / 22
17.1.25 33 / 22
17.1.24 33 / 22
17.1.23 33 / 22
17.1.22 33 / 22
17.1.21 33 / 22
17.1.20 33 / 22
17.1.19 33 / 22
17.1.18 33 / 22
17.1.17 33 / 22
17.1.16 33 / 22
17.1.15 33 / 22
17.1.14 33 / 22
17.1.13 33 / 22
17.1.12 33 / 22
17.1.11 33 / 22
17.1.10 33 / 22
17.1.9 33 / 22
17.1.8 33 / 25
17.1.7 33 / 25
17.1.6 33 / 25
17.1.5 33 / 25
17.1.4 33 / 25
17.1.2 33 / 25
17.1.1 33 / 25
17.1.0 33 / 24
17.0.27 34 / 34
17.0.26 34 / 33
17.0.25 34 / 33
17.0.15 34 / 33
17.0.13 34 / 33
17.0.9 34 / 33
17.0.6 34 / 33
16.0.15 34 / 33

v20.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v19.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v18.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v17.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.