remeda
3
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
eranhirschtkdodolsentkiewicz
Keywords
algoalgorithmcurriedfpfunctionalgenericslodashramdastdlibtoolkittstypestypescriptunderscoreutilutilitiesutilityutils
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/hasSubObject.test-d.cjs | AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated | ai | |
| source-diff | obfuscated-file:dist/evolve.test-d.cjs | AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated | ai | |
| source-diff | obfuscated-file:dist/flat.test-d.cjs | AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated | ai | |
| source-diff | obfuscated-file:dist/fromKeys.test-d.cjs | AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated | ai | |
| source-diff | obfuscated-file:dist/conditional.test-d.cjs | AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated | ai | |
| source-diff | large-new-source-files | AI (source-diff): tsup dist bundle emits many per-function .cjs files; expected build output. | ai | |
| provenance | slsa-provenance | AI (provenance): Remeda publishes via CI/CD with Sigstore attestation; stable supply chain signal for this package. | ai | |
| typosquat | typosquat.levenshtein:ramda | AI (typosquat): Remeda is a legitimate, well-established utility library intentionally inspired by ramda; the name similarity is by design, not impersonation. Stable false positive for this package. | ai |
v2.0.2
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.