workbox-precaching
This module efficiently precaches assets.
51
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
gauntfacejeffposnickaddyosmaniphilipwaltontropicadriwestonrutertomayackhempeniusswissspidy
Keywords
workboxworkboxjsservice workersw
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.dev.v2.1.0.js | AI (source-diff): Minified build artifact from Google's Workbox build pipeline; Apache 2.0 license header present, source maps included, content is legitimate service worker precaching code. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.prod.v2.1.0.mjs | AI (source-diff): Minified ESM production build artifact from Google's Workbox build pipeline; Apache 2.0 license header present, source maps included, content is legitimate service worker precaching code. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.dev.v2.1.0.mjs | AI (source-diff): Minified ESM build artifact from Google's Workbox build pipeline; Apache 2.0 license header present, source maps included, content is legitimate service worker precaching code. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.prod.v2.1.0.js | AI (source-diff): Minified production build artifact from Google's Workbox build pipeline; Apache 2.0 license header present, source maps included, content is legitimate service worker precaching code. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.dev.v2.0.2-rc1-2.0.2-rc1.0.mjs | AI (source-diff): Standard minified ES module build artifact produced by gulp build for the official Google Workbox library. Apache 2.0 header present; content is legitimate service worker caching code. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.prod.v2.0.2-rc1-2.0.2-rc1.0.js | AI (source-diff): Standard minified build artifact produced by gulp build for the official Google Workbox library. Apache 2.0 header present; content is legitimate service worker caching code. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.dev.v2.0.2-rc1-2.0.2-rc1.0.js | AI (source-diff): Standard minified build artifact produced by gulp build for the official Google Workbox library. Apache 2.0 header present; content is legitimate service worker caching code. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.prod.v2.0.2-rc1-2.0.2-rc1.0.mjs | AI (source-diff): Standard minified ES module build artifact produced by gulp build for the official Google Workbox library. Apache 2.0 header present; content is legitimate service worker caching code. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.prod.v2.0.3.mjs | AI (source-diff): Standard minified ESM build artifact from Google's Workbox project. Apache-licensed, workbox-specific caching logic, no malicious content. Minification is expected for this package. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.dev.v2.0.3.js | AI (source-diff): Standard minified build artifact from Google's Workbox project. Apache-licensed, workbox-specific caching logic, no malicious content. Minification is expected for this package. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.prod.v2.0.3.js | AI (source-diff): Standard minified build artifact from Google's Workbox project. Apache-licensed, workbox-specific caching logic, no malicious content. Minification is expected for this package. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.dev.v2.0.3.mjs | AI (source-diff): Standard minified ESM build artifact from Google's Workbox project. Apache-licensed, workbox-specific caching logic, no malicious content. Minification is expected for this package. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.prod.v1.3.0.mjs | AI (source-diff): Standard minified production ESM build artifact from Workbox's gulp build pipeline; declared as package module entry point. Pattern is stable for this package. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.dev.v1.3.0.js | AI (source-diff): Standard minified build artifact from Workbox's gulp build pipeline; Google copyright header and workbox-specific logic confirm legitimacy. Pattern is stable for this package. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.dev.v1.3.0.mjs | AI (source-diff): Standard minified ESM build artifact from Workbox's gulp build pipeline; Google copyright header and workbox-specific logic confirm legitimacy. Pattern is stable for this package. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.prod.v1.3.0.js | AI (source-diff): Standard minified production build artifact from Workbox's gulp build pipeline; declared as package main entry point. Pattern is stable for this package. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.prod.v2.0.0.mjs | AI (source-diff): Standard minified ES module production build artifact from Google's Workbox project; Apache 2.0 licensed, accompanied by source maps, contains only service worker caching logic. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.dev.v2.0.0.js | AI (source-diff): Standard minified build artifact from Google's Workbox project; Apache 2.0 licensed, accompanied by source maps, contains only service worker caching logic. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.prod.v2.0.0.js | AI (source-diff): Standard minified production build artifact from Google's Workbox project; Apache 2.0 licensed, accompanied by source maps, contains only service worker caching logic. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.dev.v2.0.0.mjs | AI (source-diff): Standard minified ES module build artifact from Google's Workbox project; Apache 2.0 licensed, accompanied by source maps, contains only service worker caching logic. | ai | |
| source-diff | obfuscated-file:build/workbox-precaching.prod.js | AI (source-diff): Production build artifact (minified browser JS) for a Google Workbox library. The code is clearly a service worker precaching implementation with no malicious patterns. Expected for this package type. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): workbox-core is the official shared core of the Workbox ecosystem, published by the same Google team. Adding it as a dependency in v4.0.0 is part of the documented modular refactor. | ai | |
| source-diff | large-new-source-files | AI (source-diff): v4.0.0 was a major architectural rewrite of Workbox; new source files are expected and consistent with the legitimate release history. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.dev.v1.2.0.js | AI (source-diff): workbox-precaching ships minified build bundles as its primary distribution format; these are standard bundler outputs with Apache 2.0 headers, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.prod.v1.2.0.mjs | AI (source-diff): workbox-precaching ships minified build bundles as its primary distribution format; these are standard bundler outputs with Apache 2.0 headers, not malicious obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance by years; no-provenance is expected for this vintage Google package. | ai | |
| source-diff | obfuscated-file:build/modules/workbox-precaching.dev.v1.2.0.mjs | AI (source-diff): workbox-precaching ships minified build bundles as its primary distribution format; these are standard bundler outputs with Apache 2.0 headers, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:build/importScripts/workbox-precaching.prod.v1.2.0.js | AI (source-diff): workbox-precaching ships minified build bundles as its primary distribution format; these are standard bundler outputs with Apache 2.0 headers, not malicious obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of snugug alongside addition of tomayac reflects a routine maintainer handoff within Google's Workbox team, not a hostile takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): tomayac is a known Google engineer; addition is consistent with legitimate team transition within the GoogleChrome/workbox project. | ai | |
| provenance | publisher-changed | AI (provenance): tomayac is a known Google DevRel engineer; transition from tropicadri to tomayac is consistent with internal Google team rotation for the Workbox project. | ai |
Versions (showing 51 of 62)
| Version | Deps | Published |
|---|---|---|
| 7.4.1 | 3 / 0 | |
| 7.4.0 | 3 / 0 | |
| 7.3.0 | 3 / 0 | |
| 7.1.0 | 3 / 0 | |
| 7.0.0 | 3 / 0 | |
| 6.6.1 | 3 / 0 | |
| 6.6.0 | 3 / 0 | |
| 6.5.4 | 3 / 0 | |
| 6.5.3 | 3 / 0 | |
| 6.5.2 | 3 / 0 | |
| 6.5.1 | 3 / 0 | |
| 6.5.0 | 3 / 0 | |
| 6.4.2 | 3 / 0 | |
| 6.4.1 | 3 / 0 | |
| 6.4.0 | 3 / 0 | |
| 6.3.0 | 3 / 0 | |
| 6.2.4 | 3 / 0 | |
| 6.2.3 | 3 / 0 | |
| 6.2.2 | 3 / 0 | |
| 6.2.1 | 3 / 0 | |
| 6.2.0 | 3 / 0 | |
| 6.1.5 | 3 / 0 | |
| 6.1.2 | 3 / 0 | |
| 6.1.1 | 3 / 0 | |
| 6.1.0 | 3 / 0 | |
| 6.0.2 | 3 / 0 | |
| 6.0.0 | 3 / 0 | |
| 5.1.4 | 1 / 0 | |
| 5.1.3 | 1 / 0 | |
| 5.1.2 | 1 / 0 | |
| 5.1.1 | 1 / 0 | |
| 5.1.0 | 1 / 0 | |
| 5.0.0 | 1 / 0 | |
| 4.3.1 | 1 / 0 | |
| 4.3.0 | 1 / 0 | |
| 4.2.0 | 1 / 0 | |
| 4.1.1 | 1 / 0 | |
| 4.1.0 | 1 / 0 | |
| 4.0.0 | 1 / 0 | |
| 3.6.3 | 1 / 0 | |
| 3.6.2 | 1 / 0 | |
| 3.6.1 | 1 / 0 | |
| 3.6.0 | 1 / 0 | |
| 3.5.0 | 1 / 0 | |
| 3.4.1 | 1 / 0 | |
| 3.3.1 | 1 / 0 | |
| 3.3.0 | 1 / 0 | |
| 3.2.0 | 1 / 0 | |
| 3.1.0 | 1 / 0 | |
| 3.0.1 | 1 / 0 | |
| 3.0.0 | 1 / 0 |
v7.4.0
2 findings
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
INFO
Publisher changed: tomayac → swissspidy (on 2025-11-19)
provenance
[Accepted risk] This version was published by a different npm account than previous versions on 2025-11-19. This could indicate a legitimate maintainer transition or an account compromise.