lib0
> Monorepo of isomorphic utility functions
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/test.cjs | AI (source-diff): Base64 nyan-cat GIF in test reporter output; stable benign artifact of the build. | ai | |
| source-diff | encoded-string-file:dist/test.js | AI (source-diff): nyanCatImage GIF in test reporter; benign test asset. | ai | |
| source-diff | encoded-string-file:dist/testing.js | AI (source-diff): nyanCatImage GIF in test reporter; benign test asset. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Legitimate first release of a now-trusted, widely-used library. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Early version predates README/description polish; package is well-established. | ai | |
| source-diff | encoded-string-file:testing.js | AI (source-diff): Base64-encoded GIF image (Nyan Cat) for test runner output; stable across versions. | ai | |
| source-diff | encoded-string-file:dist/testing.cjs | AI (source-diff): Base64-encoded Nyan Cat GIF used as test fixture; stable across versions. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Trusted maintainer (dmonad/yjs ecosystem) resumed publishing; not indicative of takeover. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): lib0 is a binary/encoding utility library; Buffer.from(s, 'base64') is core functionality, not obfuscation. | ai |
Versions (showing 100 of 115)
| Version | Deps | Published |
|---|---|---|
| 0.2.117 | 1 / 7 | |
| 0.2.116 | 1 / 7 | |
| 0.2.115 | 1 / 7 | |
| 0.2.114 | 1 / 7 | |
| 0.2.112 | 1 / 7 | |
| 0.2.111 | 1 / 7 | |
| 0.2.110 | 1 / 7 | |
| 0.2.109 | 1 / 7 | |
| 0.2.108 | 1 / 7 | |
| 0.2.107 | 1 / 7 | |
| 0.2.106 | 1 / 7 | |
| 0.2.105 | 1 / 7 | |
| 0.2.104 | 1 / 7 | |
| 0.2.103 | 1 / 7 | |
| 0.2.102 | 1 / 7 | |
| 0.2.101 | 1 / 7 | |
| 0.2.100 | 1 / 7 | |
| 0.2.99 | 1 / 7 | |
| 0.2.98 | 1 / 7 | |
| 0.2.97 | 1 / 7 | |
| 0.2.96 | 1 / 7 | |
| 0.2.95 | 1 / 7 | |
| 0.2.94 | 1 / 7 | |
| 0.2.93 | 1 / 7 | |
| 0.2.92 | 1 / 7 | |
| 0.2.91 | 1 / 7 | |
| 0.2.90 | 1 / 7 | |
| 0.2.89 | 1 / 7 | |
| 0.2.88 | 1 / 7 | |
| 0.2.87 | 1 / 7 | |
| 0.2.86 | 1 / 7 | |
| 0.2.85 | 1 / 7 | |
| 0.2.84 | 1 / 7 | |
| 0.2.83 | 1 / 7 | |
| 0.2.82 | 1 / 7 | |
| 0.2.81 | 1 / 7 | |
| 0.2.80 | 1 / 7 | |
| 0.2.79 | 1 / 7 | |
| 0.2.78 | 1 / 7 | |
| 0.2.77 | 1 / 7 | |
| 0.2.76 | 1 / 7 | |
| 0.2.75 | 1 / 7 | |
| 0.2.74 | 1 / 7 | |
| 0.2.73 | 1 / 7 | |
| 0.2.72 | 1 / 7 | |
| 0.2.71 | 1 / 7 | |
| 0.2.70 | 1 / 7 | |
| 0.2.69 | 1 / 7 | |
| 0.2.68 | 1 / 7 | |
| 0.2.67 | 1 / 8 | |
| 0.2.66 | 1 / 8 | |
| 0.2.65 | 1 / 8 | |
| 0.2.64 | 1 / 8 | |
| 0.2.63 | 1 / 10 | |
| 0.2.62 | 1 / 10 | |
| 0.2.61 | 1 / 10 | |
| 0.2.60 | 1 / 10 | |
| 0.2.59 | 1 / 10 | |
| 0.2.58 | 1 / 10 | |
| 0.2.57 | 1 / 10 | |
| 0.2.56 | 1 / 10 | |
| 0.2.55 | 1 / 10 | |
| 0.2.54 | 1 / 10 | |
| 0.2.53 | 1 / 10 | |
| 0.2.52 | 1 / 10 | |
| 0.2.51 | 1 / 10 | |
| 0.2.50 | 1 / 10 | |
| 0.2.49 | 1 / 10 | |
| 0.2.48 | 1 / 10 | |
| 0.2.43 | 1 / 10 | |
| 0.2.33 | 1 / 10 | |
| 0.2.32 | 1 / 10 | |
| 0.2.31 | 1 / 10 | |
| 0.2.28 | 1 / 10 | |
| 0.2.27 | 1 / 10 | |
| 0.2.26 | 1 / 10 | |
| 0.2.25 | 1 / 10 | |
| 0.2.24 | 1 / 10 | |
| 0.2.23 | 1 / 10 | |
| 0.2.22 | 1 / 10 | |
| 0.2.21 | 1 / 10 | |
| 0.2.20 | 1 / 10 | |
| 0.2.19 | 1 / 10 | |
| 0.2.17 | 1 / 8 | |
| 0.2.16 | 1 / 8 | |
| 0.2.15 | 1 / 8 | |
| 0.2.14 | 1 / 8 | |
| 0.2.13 | 1 / 8 | |
| 0.2.12 | 1 / 8 | |
| 0.2.11 | 1 / 8 | |
| 0.2.10 | 1 / 8 | |
| 0.2.9 | 1 / 8 | |
| 0.2.8 | 1 / 8 | |
| 0.2.7 | 1 / 8 | |
| 0.2.6 | 1 / 8 | |
| 0.2.5 | 1 / 8 | |
| 0.2.4 | 1 / 8 | |
| 0.2.3 | 1 / 8 | |
| 0.2.2 | 1 / 8 | |
| 0.2.1 | 1 / 8 |
v0.2.93
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.92
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.91
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.90
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.89
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.88
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.87
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.86
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.85
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.84
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.83
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.82
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.81
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.80
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.79
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.76
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.75
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.74
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.73
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.72
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.71
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.70
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.69
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.68
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.67
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.66
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.65
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.64
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.63
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.62
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.61
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.60
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.58
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.55
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.53
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.52
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.51
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.50
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.49
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.43
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.33
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.32
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.31
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.28
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.27
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.26
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.25
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.17
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.16
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.15
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.9
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.8
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.7
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.6
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.5
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.4
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.3
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.