flatten
Flatten arbitrarily nested arrays into a non-nested list of non-array items. Maintained for legacy compatibility.
6
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jesusabdullahjfhbrookmk-pmb
Keywords
arrayflatten
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Package is 13+ years old; 0.0.0 was common in early npm era. Publisher has strong track record. Not a malware indicator for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Tiny payload and no deps are consistent with a simple array-flatten utility. Legitimate minimal package from a trusted long-standing publisher. | ai | |
| provenance | publisher-changed | AI (provenance): mk-pmb is the documented new maintainer; repo URL points to their fork, description explicitly states legacy maintenance. Legitimate handoff, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): mk-pmb added as maintainer is consistent with the documented ownership transfer; no malicious indicators present. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by mk-pmb's publish is explained by the original author abandoning the package and mk-pmb adopting it for legacy compatibility. No code changes introduced. | ai |