twilsock
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-exfil-services | AI (semgrep): URL is in a documentation comment in bundled output, not executed code. | ai | |
| phantom-deps | phantom-dep:iso8601-duration | AI (phantom-deps): Declared dep referenced in config; stable FP for this package. | ai |
v0.13.11
2 findingsURL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) 7865 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 7866 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 7867 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 7868 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 7869 | var namedCaptures = result.groups;
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.10
2 findingsURL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) 7865 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 7866 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 7867 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 7868 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 7869 | var namedCaptures = result.groups;
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.9
2 findingsURL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) 7865 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 7866 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 7867 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 7868 | for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j])); 7869 | var namedCaptures = result.groups;
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.