← Home

git-spawned-stream

Create a readable stream from a spawned git process.

4
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

alessioalex

Keywords

spawnedgitstream

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): This package's core purpose is spawning git processes as readable streams; child_process.spawn is fundamental to its design, not a malicious indicator. ai
provenance no-provenance AI (provenance): Package is 11+ years old, predating Sigstore provenance on npm. Absence is expected and not a risk signal for this established package. ai

Versions (showing 4 of 4)

Version Deps Published
1.0.1 2 / 3
1.0.0 2 / 3
0.1.1 2 / 3
0.1.0 2 / 3