tree-sitter-css
1
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
maxbrunsfelddaviwilatom-teamdarangi
Keywords
incrementalparsingtree-sittercss
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:install | AI (install-scripts): node-gyp-build is the standard install pattern for native Node.js addons shipping prebuilts; stable and expected for tree-sitter grammar packages. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Prebuilt .node binaries are the standard distribution mechanism for tree-sitter grammar bindings; consistent with the official tree-sitter org's packaging pattern. | ai | |
| phantom-deps | phantom-dep:node-addon-api | AI (phantom-deps): node-addon-api is a compile-time dependency referenced in binding.gyp, not a runtime JS import; phantom-dep finding is a stable false positive for native addon packages. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 0.25.0 | 2 / 4 |