@babel/plugin-syntax-top-level-await
Allow parsing of top-level await in modules
9
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
hzoologanfsmythdanezexistentialismnicolo-ribaudojlhwung
Keywords
babel-plugin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): jlhwung is a known Babel core team member; publisher rotation within the Babel team is expected and not a security concern for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): jlhwung is a well-established Babel core contributor; adding them as maintainer is a legitimate team operation, not a takeover. | ai | |
| provenance | no-provenance | AI (provenance): Package predates widespread Sigstore provenance adoption; published by a trusted Babel core team member from the official monorepo. | ai | |
| bogus-package | bogus-package | AI (bogus-package): loganfsmyth and hzoo are well-known Babel core contributors; spam flags are false positives for the @babel namespace. Tiny payload is expected for a syntax plugin. | ai |