← Home

pkg-prebuilds

2
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

julusian

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Moved from personal npm publish to GitHub Actions CI/CD with SLSA provenance; same repo owner. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by stable utility; CI/CD provenance confirms legitimate publish. ai
semgrep semgrep:child-process-import AI (semgrep): CLI tool for managing native prebuilds; child_process use is expected and documented. ai
semgrep semgrep:dynamic-require AI (semgrep): verify.mjs loads a user-supplied options file by design; not arbitrary module loading. ai

Versions (showing 2 of 2)

Version Deps Published
1.1.0 0 / 0
1.0.0 1 / 0