putout
26
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
coderaiser
Keywords
asttransformputout-scriptcodemodeslintbabelpluginlintvariableunused
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@putout/plugin-apply-push | AI (dependencies): First-party putout plugin from same maintainer/monorepo. | ai | |
| phantom-deps | phantom-dep:@putout/plugin-apply-push | AI (phantom-deps): Plugin loaded dynamically by putout's plugin engine, not statically imported. | ai | |
| dependencies | unvetted-dep:@putout/operator-wasm | AI (dependencies): First-party putout sibling package, consistent naming/versioning with rest of monorepo. | ai | |
| phantom-deps | phantom-dep:@putout/plugin-new | AI (phantom-deps): Plugin loaded dynamically by config, not imported; core architecture pattern. | ai | |
| dependencies | unvetted-dep:@putout/plugin-convert-expression-to-params | AI (dependencies): First-party @putout scoped plugin, same maintainer/monorepo. | ai | |
| dependencies | unvetted-dep:@putout/plugin-apply-destructuring | AI (dependencies): First-party monorepo plugin, same publisher/org, stable across versions. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): Used via config/loader indirection, standard debug usage. | ai | |
| phantom-deps | phantom-dep:@putout/plugin-esm | AI (phantom-deps): Plugin referenced in config; stable pattern for putout's plugin architecture. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @putout/types is a first-party scoped dep from the same author/namespace; low risk for this package. | ai | |
| dependencies | unvetted-dep:@putout/processor-css | AI (dependencies): First-party @putout scoped package; consistent with putout's plugin ecosystem pattern. | ai | |
| phantom-deps | phantom-dep:is-relative | AI (phantom-deps): Same dynamic-loading pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@putout/cli-cache | AI (phantom-deps): First-party sub-package loaded dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:find-up | AI (phantom-deps): putout loads plugins/formatters dynamically; phantom-dep heuristic is a stable false positive for this monorepo. | ai | |
| phantom-deps | phantom-dep:@putout/cli-ruler | AI (phantom-deps): First-party sub-package loaded dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@putout/cli-match | AI (phantom-deps): First-party sub-package loaded dynamically; stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Established package; lack of provenance is common and not a risk signal here. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads user-controlled PUTOUT_CONFIG_FILE env var path — intentional config-loading pattern for this tool. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 42.10.0 | 158 / 13 | |
| 42.8.0 | 157 / 13 | |
| 42.7.8 | 156 / 13 | |
| 42.7.2 | 155 / 13 | |
| 42.6.0 | 155 / 12 | |
| 42.5.0 | 154 / 12 | |
| 42.4.5 | 154 / 13 | |
| 42.4.3 | 154 / 13 | |
| 42.0.21 | 150 / 13 | |
| 42.0.20 | 150 / 13 | |
| 42.0.16 | 150 / 13 | |
| 41.23.0 | 148 / 13 | |
| 41.21.1 | 147 / 13 | |
| 41.21.0 | 147 / 13 | |
| 41.15.0 | 146 / 13 | |
| 41.13.0 | 146 / 13 | |
| 41.12.0 | 147 / 13 | |
| 41.11.0 | 147 / 13 | |
| 41.10.1 | 147 / 13 | |
| 41.9.2 | 147 / 13 | |
| 41.7.0 | 145 / 12 | |
| 41.6.3 | 145 / 12 | |
| 41.3.1 | 144 / 12 | |
| 41.0.9 | 145 / 13 | |
| 41.0.5 | 147 / 13 | |
| 40.14.0 | 162 / 14 |
v42.10.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v42.8.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.