dax
Cross platform shell tools inspired by zx.
13
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
dsherret
Keywords
shellscriptingspawnprocess
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:esm/mod.js | AI (source-diff): Base64 is wasm-bindgen compiled WASM binary (rs_lib.js); stable pattern for this package. | ai | |
| source-diff | encoded-string-file:script/mod.js | AI (source-diff): Same wasm-bindgen WASM binary pattern in CJS bundle; stable for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() appears in WASM JS bindings glue code — standard pattern, not obfuscation. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Shell scripting library legitimately enumerates env vars to pass to child processes. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 0.49.0 | 1 / 3 | |
| 0.48.6 | 1 / 3 | |
| 0.48.5 | 1 / 3 | |
| 0.48.4 | 1 / 3 | |
| 0.48.3 | 1 / 3 | |
| 0.48.2 | 1 / 3 | |
| 0.48.1 | 1 / 3 | |
| 0.48.0 | 1 / 3 | |
| 0.47.0 | 1 / 3 | |
| 0.46.1 | 1 / 3 | |
| 0.46.0 | 2 / 2 | |
| 0.45.0 | 2 / 2 | |
| 0.44.2 | 2 / 2 |
v0.49.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.6
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.5
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.48.4
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.