← Home

protobufjs-cli

26
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dcodefenstergoogle-wombot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): CLI companion to protobufjs; low-value signals are false positives for this package. ai
npm-metadata url-dep:protobufjs AI (npm-metadata): Monorepo file:.. devDependency pattern; not a runtime dep. ai
source-diff obfuscated-file:lib/catharsis/lib/parser.js AI (source-diff): Peggy-generated parser, clearly annotated; not obfuscated. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher with SLSA provenance; consistent with official CI/CD publishing for this established package. ai
semgrep semgrep:child-process-spawn AI (semgrep): CLI tool legitimately spawns jsdoc via child_process; stable pattern for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): pbjs intentionally supports user-specified custom targets via --target flag; dynamic require is a documented feature, not a security risk for this CLI tool. ai
phantom-deps phantom-dep:semver AI (phantom-deps): semver is a declared runtime dependency in package.json; phantom-dep finding is a false positive likely due to indirect import patterns. ai
semgrep semgrep:child-process-exec AI (semgrep): child_process.exec is used to run jsdoc (a declared dependency) for TypeScript generation; command is constructed from known paths, not arbitrary user input. ai
semgrep semgrep:child-process-import AI (semgrep): pbts uses child_process to invoke jsdoc for TypeScript definition generation; this is the documented and expected behavior of this CLI tool. ai

Versions (showing 26 of 26)

Version Deps Published
2.6.1 7 / 1
2.6.0 8 / 1
2.5.7 8 / 1
2.5.6 8 / 1
2.5.5 8 / 1
2.5.4 8 / 1
2.5.2 8 / 1
2.5.1 8 / 1
2.5.0 10 / 1
2.4.2 10 / 1
2.4.1 10 / 1
2.4.0 10 / 1
2.3.0 10 / 1
2.2.1 10 / 1
2.2.0 10 / 1
2.0.3 10 / 1
2.0.2 10 / 1
2.0.1 10 / 1
2.0.0 10 / 1
1.3.3 10 / 1
1.3.2 10 / 1
1.3.1 10 / 1
1.3.0 10 / 1
1.2.2 10 / 1
1.2.1 10 / 1
1.1.2 10 / 1

v2.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.