ffi-rs
A module written in Rust and N-API provides interface (FFI) features for Node.js
51
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
zhangyuang
Keywords
ffirustnode.jsnapi
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:ffi-rs-darwin-arm64 | AI (dependencies): Standard NAPI-RS platform binary optional dependency; this is the canonical distribution pattern for native Node.js addons. | ai | |
| dependencies | unvetted-dep:ffi-rs-linux-x64-gnu | AI (dependencies): Standard NAPI-RS platform binary optional dependency; this is the canonical distribution pattern for native Node.js addons. | ai | |
| dependencies | unvetted-dep:ffi-rs-win32-x64-msvc | AI (dependencies): Standard NAPI-RS platform binary optional dependency; this is the canonical distribution pattern for native Node.js addons. | ai | |
| dependencies | unvetted-dep:ffi-rs-linux-arm64-gnu | AI (dependencies): Standard NAPI-RS platform binary optional dependency; this is the canonical distribution pattern for native Node.js addons. | ai | |
| dependencies | unvetted-dep:ffi-rs-linux-arm64-musl | AI (dependencies): Standard NAPI-RS platform binary optional dependency; this is the canonical distribution pattern for native Node.js addons. | ai | |
| phantom-deps | phantom-dep:ffi-rs-darwin-x64 | AI (phantom-deps): Platform binary packages are loaded conditionally at runtime, not statically imported; phantom detection is a false positive for NAPI-RS packages. | ai | |
| phantom-deps | phantom-dep:ffi-rs-linux-arm64-musl | AI (phantom-deps): Platform binary packages are loaded conditionally at runtime, not statically imported; phantom detection is a false positive for NAPI-RS packages. | ai | |
| phantom-deps | phantom-dep:ffi-rs-linux-arm64-gnu | AI (phantom-deps): Platform binary packages are loaded conditionally at runtime, not statically imported; phantom detection is a false positive for NAPI-RS packages. | ai | |
| phantom-deps | phantom-dep:ffi-rs-win32-x64-msvc | AI (phantom-deps): Platform binary packages are loaded conditionally at runtime, not statically imported; phantom detection is a false positive for NAPI-RS packages. | ai | |
| phantom-deps | phantom-dep:ffi-rs-linux-x64-gnu | AI (phantom-deps): Platform binary packages are loaded conditionally at runtime, not statically imported; phantom detection is a false positive for NAPI-RS packages. | ai | |
| dependencies | unvetted-dep:ffi-rs-darwin-x64 | AI (dependencies): Standard NAPI-RS platform binary optional dependency; this is the canonical distribution pattern for native Node.js addons. | ai | |
| phantom-deps | phantom-dep:ffi-rs-darwin-arm64 | AI (phantom-deps): Platform binary packages are loaded conditionally at runtime, not statically imported; phantom detection is a false positive for NAPI-RS packages. | ai | |
| phantom-deps | phantom-dep:@yuuang/ffi-rs-linux-arm64-musl | AI (phantom-deps): Platform-specific binary dependency declared as optional; standard NAPI pattern for multi-platform native modules. | ai | |
| phantom-deps | phantom-dep:@yuuang/ffi-rs-darwin-x64 | AI (phantom-deps): Platform-specific binary dependency declared as optional; standard NAPI pattern for multi-platform native modules. | ai | |
| phantom-deps | phantom-dep:@yuuang/ffi-rs-darwin-arm64 | AI (phantom-deps): Platform-specific binary dependency declared as optional; standard NAPI pattern for multi-platform native modules. | ai | |
| phantom-deps | phantom-dep:@yuuang/ffi-rs-linux-x64-gnu | AI (phantom-deps): Platform-specific binary dependency declared as optional; standard NAPI pattern for multi-platform native modules. | ai | |
| phantom-deps | phantom-dep:@yuuang/ffi-rs-win32-x64-msvc | AI (phantom-deps): Platform-specific binary dependency declared as optional; standard NAPI pattern for multi-platform native modules. | ai | |
| phantom-deps | phantom-dep:@yuuang/ffi-rs-linux-arm64-gnu | AI (phantom-deps): Platform-specific binary dependency declared as optional; standard NAPI pattern for multi-platform native modules. | ai | |
| phantom-deps | phantom-dep:@napi-rs/cli | AI (phantom-deps): @napi-rs/cli is used in build scripts (artifacts, universal, version); phantom-dep is expected for build tooling. | ai | |
| phantom-deps | phantom-dep:shelljs | AI (phantom-deps): shelljs is used in build scripts; phantom-dep is expected for build-time tooling dependencies. | ai | |
| phantom-deps | phantom-dep:esno | AI (phantom-deps): esno is a legitimate build/test tool used in the 'test' script; phantom-dep is expected for build-time dependencies. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process is used solely to run 'which ldd' for musl detection in N-API binary selection — a standard, benign pattern for native bindings. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): execSync('which ldd') is used for musl libc detection to select the correct prebuilt binary. Hardcoded, non-user-controlled command with no security risk. | ai |
Versions (showing 51 of 99)
| Version | Deps | Published |
|---|---|---|
| 1.3.4 | 0 / 8 | |
| 1.3.2 | 0 / 8 | |
| 1.3.1 | 0 / 8 | |
| 1.3.0 | 0 / 8 | |
| 1.2.16 | 0 / 8 | |
| 1.2.15 | 0 / 8 | |
| 1.2.14 | 0 / 8 | |
| 1.2.13 | 0 / 8 | |
| 1.2.12 | 0 / 8 | |
| 1.2.11 | 0 / 8 | |
| 1.2.10 | 0 / 9 | |
| 1.2.9 | 0 / 9 | |
| 1.2.8 | 0 / 9 | |
| 1.2.6 | 0 / 9 | |
| 1.2.5 | 0 / 9 | |
| 1.2.4 | 0 / 9 | |
| 1.2.3 | 0 / 9 | |
| 1.2.2 | 0 / 9 | |
| 1.2.1 | 0 / 9 | |
| 1.2.0 | 0 / 9 | |
| 1.1.1 | 0 / 9 | |
| 1.1.0 | 0 / 9 | |
| 1.0.99 | 0 / 9 | |
| 1.0.98 | 0 / 9 | |
| 1.0.97 | 0 / 9 | |
| 1.0.96 | 0 / 9 | |
| 1.0.95 | 0 / 9 | |
| 1.0.94 | 0 / 9 | |
| 1.0.93 | 0 / 9 | |
| 1.0.91 | 0 / 9 | |
| 1.0.90 | 0 / 9 | |
| 1.0.89 | 0 / 9 | |
| 1.0.88 | 0 / 9 | |
| 1.0.87 | 0 / 9 | |
| 1.0.86 | 0 / 9 | |
| 1.0.85 | 0 / 9 | |
| 1.0.84 | 0 / 9 | |
| 1.0.83 | 0 / 9 | |
| 1.0.82 | 0 / 9 | |
| 1.0.81 | 0 / 9 | |
| 1.0.80 | 0 / 9 | |
| 1.0.79 | 0 / 9 | |
| 1.0.78 | 0 / 9 | |
| 1.0.77 | 0 / 9 | |
| 1.0.76 | 0 / 9 | |
| 1.0.75 | 0 / 9 | |
| 1.0.74 | 0 / 9 | |
| 1.0.73 | 0 / 9 | |
| 1.0.72 | 0 / 9 | |
| 1.0.71 | 0 / 9 | |
| 1.0.70 | 0 / 9 |
v1.3.4
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.