lunr-languages
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:eval-usage | AI (semgrep): eval in bundled require.js demo shim; benign AMD loader pattern. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Template-engine render compile in wordcut.js; standard pattern. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 1.20.0 | 0 / 4 | |
| 1.19.0 | 0 / 4 | |
| 1.18.0 | 0 / 4 | |
| 1.17.0 | 0 / 4 | |
| 1.15.0 | 0 / 4 | |
| 1.14.0 | 0 / 5 | |
| 1.13.0 | 0 / 5 | |
| 1.12.0 | 0 / 5 |
v1.14.0
2 findingseval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/MihaiValentin/lunr-languages/blob/18787d6dd8277216bba54f19bdeaad93427f7a32/demos/lib/require.js#L36 34 | (e.addEventListener("load",b.onScriptLoad,!1),e.addEventListener("error",b.onScriptError,!1)),e.src=d,J=e,D?y.in 35 | O),s=s.replace(Q,""),g.jsExtRegExp.test(s)&&(s=I),q.deps=q.deps?q.deps.concat(s):[s],!0});define=function(b,c,d) > 36 | (b=e.getAttribute("data-requiremodule")),g=F[e.getAttribute("data-requirecontext")])}(g?g.defQueue:R).push([b,c,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.0
2 findingseval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/MihaiValentin/lunr-languages/blob/df2efed0c1b538d9390e2fe92d2619620205c5c5/demos/lib/require.js#L36 34 | (e.addEventListener("load",b.onScriptLoad,!1),e.addEventListener("error",b.onScriptError,!1)),e.src=d,J=e,D?y.in 35 | O),s=s.replace(Q,""),g.jsExtRegExp.test(s)&&(s=I),q.deps=q.deps?q.deps.concat(s):[s],!0});define=function(b,c,d) > 36 | (b=e.getAttribute("data-requiremodule")),g=F[e.getAttribute("data-requirecontext")])}(g?g.defQueue:R).push([b,c,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.0
2 findingseval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/MihaiValentin/lunr-languages/blob/f313734d145048be2f3681b756f9bf925aa299a1/demos/lib/require.js#L36 34 | (e.addEventListener("load",b.onScriptLoad,!1),e.addEventListener("error",b.onScriptError,!1)),e.src=d,J=e,D?y.in 35 | O),s=s.replace(Q,""),g.jsExtRegExp.test(s)&&(s=I),q.deps=q.deps?q.deps.concat(s):[s],!0});define=function(b,c,d) > 36 | (b=e.getAttribute("data-requiremodule")),g=F[e.getAttribute("data-requirecontext")])}(g?g.defQueue:R).push([b,c,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.