← Home

@ampproject/remapping

Remap sequential sourcemaps through transformations to point at the original source code

19
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

ampproject-adminjridgewell

Keywords

sourcemapremap

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established AMP Project package with 36M weekly downloads published before Sigstore provenance was common practice; absence is expected and not a risk signal. ai
dependencies unvetted-dep:sourcemap-codec AI (dependencies): sourcemap-codec 1.4.8 is a well-known, stable source-map ecosystem library pinned to a specific version; no malicious history or concerns. ai

Versions (showing 19 of 19)

Version Deps Published
2.3.0 2 / 14
2.2.1 2 / 14
2.2.0 2 / 14
2.1.2 1 / 14
2.1.1 1 / 14
2.1.0 1 / 14
2.0.4 1 / 14
2.0.3 2 / 14
2.0.2 2 / 14
2.0.1 3 / 14
2.0.0 3 / 14
1.1.1 2 / 14
1.1.0 2 / 14
1.0.2 2 / 15
1.0.1 2 / 15
1.0.0 2 / 15
0.3.0 2 / 15
0.2.0 2 / 18
0.1.0 2 / 18