@antfu/utils
Opinionated collection of common JavaScript / TypeScript utils by @antfu
15
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
antfu
Keywords
utils
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Legitimate migration from manual npm publish to GitHub Actions CI/CD, confirmed by SLSA provenance attestation. | ai | |
| provenance | missing-githead | AI (provenance): Expected side effect of publishing via GitHub Actions CI/CD rather than manual npm publish. | ai | |
| bogus-package | bogus-package | AI (bogus-package): antfu is a prominent OSS maintainer; spam flag is a clear false positive. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 3.7M weekly downloads and 46 versions; lack of Sigstore provenance is common and not a risk signal here. | ai |