← Home

remeda

3
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

eranhirschtkdodolsentkiewicz

Keywords

algoalgorithmcurriedfpfunctionalgenericslodashramdastdlibtoolkittstypestypescriptunderscoreutilutilitiesutilityutils

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/hasSubObject.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/evolve.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/flat.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/fromKeys.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff obfuscated-file:dist/conditional.test-d.cjs AI (source-diff): tsup-bundled type-test fixture, minified not obfuscated ai
source-diff large-new-source-files AI (source-diff): tsup dist bundle emits many per-function .cjs files; expected build output. ai
provenance slsa-provenance AI (provenance): Remeda publishes via CI/CD with Sigstore attestation; stable supply chain signal for this package. ai
typosquat typosquat.levenshtein:ramda AI (typosquat): Remeda is a legitimate, well-established utility library intentionally inspired by ramda; the name similarity is by design, not impersonation. Stable false positive for this package. ai

Versions (showing 3 of 103)

Version Deps Published
2.0.2 1 / 19
2.0.1 1 / 19
2.0.0 1 / 19

v2.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.