cbor-x
Ultra-fast and conformant CBOR (RFC 8949) implementation with support for numerous tag extensions including records and structured cloning
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): createRequire fallback loader for optional native cbor-extract binding, not attacker-controlled. | ai | |
| dependencies | unvetted-dep:cbor-extract | AI (dependencies): Official sibling package by same author for native binary acceleration. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): Known implicit build dependency. | ai | |
| phantom-deps | phantom-dep:cbor-extract | AI (phantom-deps): Referenced via optional native binding loader, not direct import. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): The new Function() call is a feature-detection probe in a try/catch to check eval support, not dynamic execution of untrusted input. This is a stable, documented pattern in cbor-x's JIT decoder. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 1.6.4 | 0 / 12 | |
| 1.6.3 | 0 / 12 | |
| 1.6.0 | 0 / 12 | |
| 1.5.7 | 0 / 12 | |
| 1.2.1 | 2 / 10 | |
| 1.0.0 | 2 / 10 |
v1.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.