engine
Template engine based on Lo-Dash template, but adds features like the ability to register helpers and more easily set data to be used as context in templates.
14
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
doowbjonschlinkert
Keywords
compiledataengineerbhelperhelperslodashregisterrenderrenderertemplatetemplatesunderscore
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:get-value | AI (phantom-deps): lazy-cache pattern causes static phantom-dep false positives in this package; dependency is legitimately used at runtime. | ai | |
| phantom-deps | phantom-dep:set-value | AI (phantom-deps): lazy-cache pattern causes static phantom-dep false positives in this package; dependency is legitimately used at runtime. | ai | |
| phantom-deps | phantom-dep:collection-visit | AI (phantom-deps): lazy-cache pattern causes static phantom-dep false positives in this package; dependency is legitimately used at runtime. | ai | |
| phantom-deps | phantom-dep:assign-deep | AI (phantom-deps): lazy-cache pattern causes static phantom-dep false positives in this package; dependency is legitimately used at runtime. | ai | |
| phantom-deps | phantom-dep:object.omit | AI (phantom-deps): lazy-cache pattern causes static phantom-dep false positives in this package; dependency is legitimately used at runtime. | ai | |
| phantom-deps | phantom-dep:kind-of | AI (phantom-deps): jonschlinkert packages use lazy-cache for deferred requires; static analysis cannot detect dynamic requires, making this a stable false positive. | ai | |
| source-diff | net-exec-file:index.js | AI (source-diff): index.js is a legitimate template engine implementation; require() calls are not network calls and the constructor pattern is not dynamic code execution. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lazy-cache | AI (phantom-deps): lazy-cache is likely used indirectly via lib/utils.js; phantom-dep detection doesn't account for indirect imports in utility modules. | ai | |
| phantom-deps | phantom-dep:shallow-clone | AI (phantom-deps): shallow-clone is likely used indirectly via lib/utils.js; same pattern as lazy-cache false positive. | ai | |
| provenance | publisher-changed | AI (provenance): The package.json has always attributed authorship to jonschlinkert; the 2016 publisher change reflects a legitimate transfer to the original author. No malicious signals accompany it. | ai |