← Home

remeda

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

eranhirschtkdodolsentkiewicz

Keywords

algoalgorithmcurriedfpfunctionalgenericslodashramdastdlibtoolkittstypestypescriptunderscoreutilutilitiesutilityutils

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/hasSubObject.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/evolve.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/flat.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/fromKeys.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/conditional.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff large-new-source-files AI (source-diff): tsup dist bundle emits many per-function .cjs files; expected build output. ai
provenance slsa-provenance AI (provenance): Remeda publishes via CI/CD with Sigstore attestation; stable supply chain signal for this package. ai
typosquat typosquat.levenshtein:ramda AI (typosquat): Remeda is a legitimate, well-established utility library intentionally inspired by ramda; the name similarity is by design, not impersonation. Stable false positive for this package. ai

Versions (showing 100 of 103)

Version Deps Published
2.39.0 0 / 25
2.38.0 0 / 25
2.37.0 0 / 25
2.36.0 0 / 25
2.35.0 0 / 25
2.34.1 0 / 25
2.34.0 0 / 25
2.33.7 0 / 25
2.33.6 0 / 25
2.33.5 0 / 25
2.33.4 0 / 24
2.33.3 0 / 24
2.33.2 0 / 24
2.33.1 0 / 24
2.33.0 0 / 24
2.32.2 1 / 23
2.32.1 1 / 23
2.32.0 1 / 23
2.31.1 1 / 23
2.31.0 1 / 23
2.30.0 1 / 23
2.29.0 1 / 23
2.28.0 1 / 23
2.27.2 1 / 23
2.27.1 1 / 23
2.27.0 1 / 23
2.26.1 1 / 23
2.26.0 1 / 23
2.25.0 1 / 23
2.24.1 1 / 23
2.24.0 1 / 23
2.23.3 1 / 23
2.23.2 1 / 23
2.23.1 1 / 23
2.23.0 1 / 23
2.22.6 1 / 23
2.22.5 1 / 23
2.22.4 1 / 23
2.22.3 1 / 22
2.22.2 1 / 22
2.22.1 1 / 21
2.22.0 1 / 21
2.21.9 1 / 21
2.21.8 1 / 21
2.21.7 1 / 21
2.21.6 1 / 21
2.21.5 1 / 21
2.21.4 1 / 21
2.21.3 1 / 19
2.21.2 1 / 19
2.21.1 1 / 19
2.21.0 1 / 19
2.20.2 1 / 20
2.20.1 1 / 20
2.20.0 1 / 20
2.19.2 1 / 20
2.19.1 1 / 20
2.19.0 1 / 20
2.18.0 1 / 20
2.17.5 1 / 20
2.17.4 1 / 20
2.17.3 1 / 20
2.17.2 1 / 20
2.17.1 1 / 20
2.17.0 1 / 20
2.16.0 1 / 20
2.15.2 1 / 20
2.15.1 1 / 20
2.15.0 1 / 20
2.14.0 1 / 19
2.13.0 1 / 19
2.12.1 1 / 19
2.12.0 1 / 19
2.11.0 1 / 19
2.10.1 1 / 19
2.10.0 1 / 19
2.9.1 1 / 19
2.9.0 1 / 19
2.8.0 1 / 19
2.7.2 1 / 19
2.7.1 1 / 19
2.7.0 1 / 19
2.6.0 1 / 19
2.5.0 1 / 19
2.4.0 1 / 19
2.3.0 1 / 19
2.2.2 1 / 19
2.2.1 1 / 19
2.2.0 1 / 19
2.1.0 1 / 19
2.0.12 1 / 19
2.0.11 1 / 19
2.0.10 1 / 19
2.0.9 1 / 19
2.0.8 1 / 19
2.0.7 1 / 19
2.0.6 1 / 19
2.0.5 1 / 19
2.0.4 1 / 19
2.0.3 1 / 19
Showing 100 of 103 Next page →

v2.21.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.19.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.15.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.15.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.1

6 findings
HIGH New obfuscated file: dist/conditional.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/evolve.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/flat.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/fromKeys.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/hasSubObject.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

6 findings
HIGH New obfuscated file: dist/conditional.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/evolve.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/flat.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/fromKeys.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/hasSubObject.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.0

6 findings
HIGH New obfuscated file: dist/conditional.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/evolve.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/flat.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/fromKeys.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/hasSubObject.test-d.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.