@babel/preset-env
A Babel preset for each environment.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@babel/plugin-bugfix-safari-rest-destructuring-rhs-array | AI (dependencies): First-party @babel/ scoped bugfix plugin added in lockstep with preset-env; consistent with Babel's established release pattern. | ai | |
| phantom-deps | phantom-dep:core-js-compat | AI (phantom-deps): core-js-compat is a declared direct dependency used via data/config references in preset-env, not via ES import statements. This is the expected usage pattern for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-nullish-coalescing-operator | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-private-property-in-object | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-optional-catch-binding | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-export-namespace-from | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-unicode-sets-regex | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-object-rest-spread | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-class-static-block | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-optional-chaining | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-numeric-separator | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-class-properties | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-async-generators | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-top-level-await | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-dynamic-import | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-json-strings | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in available-plugins.js is intentional: it lazily loads @babel/plugin-syntax-* packages from a hardcoded list of names. Not arbitrary module loading. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-import-meta | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-logical-assignment-operators | AI (phantom-deps): Loaded dynamically via the available-plugins pattern; declared in package.json deps. False positive for this package. | ai | |
| phantom-deps | phantom-dep:browserslist | AI (phantom-deps): browserslist is a core runtime dependency of preset-env used for browser target resolution; phantom-dep detection is a false positive here. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): developit (Jason Miller) is a well-known, reputable JS developer; his addition to Babel maintainers is a legitimate ecosystem event, not a suspicious takeover. | ai | |
| dependencies | unvetted-dep:@nicolo-ribaudo/semver-v6 | AI (dependencies): Scoped dependency by the same maintainer as a semver replacement; stable pattern for this package. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead reflects a CI/CD publish environment change in the Babel monorepo, not a security concern. Publisher nicolo-ribaudo is a trusted Babel core maintainer. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Babel team maintainer rotation (danez, loganfsmyth → nicolo-ribaudo) is a documented, legitimate transition for this major open-source project, not a takeover. | ai | |
| bogus-package | bogus-package | AI (bogus-package): hzoo is Henry Zhu, founder of Babel — not a spam publisher. This is a false positive for the @babel/ namespace. No keywords is also normal for this monorepo package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy is an artifact of registry approval history gap, not actual npm inactivity. @babel/preset-env has been continuously maintained and published on npm. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are all @babel/plugin-transform-* replacements for deprecated @babel/plugin-proposal-* packages — a well-documented, intentional Babel project rename, not suspicious additions. | ai | |
| provenance | publisher-changed | AI (provenance): Babel monorepo uses GitHub Actions for automated publishing; transition from individual maintainer account to CI publisher is documented and expected for this package. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-dynamic-import | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-json-strings | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-export-namespace-from | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-logical-assignment-operators | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-async-generator-functions | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-unicode-property-regex | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-optional-catch-binding | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-syntax-export-namespace-from | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| dependencies | unvetted-dep:@babel/plugin-proposal-class-static-block | AI (dependencies): First-party Babel monorepo package published by the same trusted maintainer; unvetted status reflects pipeline lag, not a security concern. | ai | |
| provenance | no-provenance | AI (provenance): Published via GitHub Actions from the official babel/babel monorepo. Lack of Sigstore provenance is common and not a risk signal for this well-established package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-private-property-in-object | AI (phantom-deps): Known intentional placeholder pattern used by Babel team (version 7.21.0-placeholder-for-preset-env.2) to avoid peer dependency warnings. Documented Babel behavior. | ai | |
| dependencies | unvetted-dep:babel-plugin-polyfill-regenerator | AI (dependencies): Official Babel ecosystem polyfill plugin; legitimate dependency. | ai | |
| dependencies | unvetted-dep:babel-plugin-polyfill-corejs3 | AI (dependencies): Official Babel ecosystem polyfill plugin; legitimate dependency. | ai | |
| dependencies | unvetted-dep:@babel/preset-modules | AI (dependencies): Official Babel monorepo package; legitimate first-party dependency of @babel/preset-env. | ai | |
| dependencies | unvetted-dep:babel-plugin-polyfill-corejs2 | AI (dependencies): Official Babel ecosystem polyfill plugin; legitimate dependency. | ai | |
| dependencies | unvetted-dep:core-js-compat | AI (dependencies): core-js-compat is a well-known, legitimate dependency of @babel/preset-env for polyfill compatibility data. Not a security risk. | ai |
Versions (showing 100 of 147)
| Version | Deps | Published |
|---|---|---|
| 7.29.7 | 71 / 4 | |
| 7.29.5 | 71 / 4 | |
| 7.29.3 | 71 / 4 | |
| 7.29.2 | 70 / 4 | |
| 7.29.0 | 70 / 4 | |
| 7.28.6 | 70 / 4 | |
| 7.28.5 | 70 / 4 | |
| 7.28.3 | 70 / 4 | |
| 7.28.0 | 70 / 4 | |
| 7.27.2 | 69 / 4 | |
| 7.27.1 | 69 / 4 | |
| 7.26.9 | 69 / 4 | |
| 7.26.8 | 69 / 4 | |
| 7.26.7 | 69 / 4 | |
| 7.26.0 | 69 / 4 | |
| 7.25.9 | 68 / 4 | |
| 7.25.8 | 68 / 4 | |
| 7.25.7 | 83 / 4 | |
| 7.25.4 | 83 / 4 | |
| 7.25.3 | 83 / 4 | |
| 7.25.2 | 83 / 4 | |
| 7.25.0 | 83 / 4 | |
| 7.24.8 | 81 / 4 | |
| 7.24.7 | 81 / 4 | |
| 7.24.6 | 81 / 4 | |
| 7.24.5 | 81 / 4 | |
| 7.24.4 | 81 / 4 | |
| 7.24.3 | 80 / 4 | |
| 7.24.1 | 80 / 4 | |
| 7.24.0 | 80 / 4 | |
| 7.23.9 | 80 / 4 | |
| 7.23.8 | 80 / 4 | |
| 7.23.7 | 80 / 4 | |
| 7.23.6 | 80 / 4 | |
| 7.23.5 | 80 / 4 | |
| 7.23.3 | 80 / 4 | |
| 7.23.2 | 80 / 4 | |
| 7.22.20 | 80 / 4 | |
| 7.22.15 | 80 / 4 | |
| 7.22.14 | 80 / 4 | |
| 7.22.10 | 80 / 4 | |
| 7.22.9 | 80 / 4 | |
| 7.22.7 | 80 / 4 | |
| 7.22.6 | 80 / 4 | |
| 7.22.5 | 80 / 4 | |
| 7.22.4 | 80 / 4 | |
| 7.22.2 | 80 / 4 | |
| 7.22.1 | 80 / 4 | |
| 7.22.0 | 79 / 4 | |
| 7.21.5 | 76 / 4 | |
| 7.21.4 | 75 / 4 | |
| 7.20.2 | 75 / 4 | |
| 7.19.4 | 75 / 4 | |
| 7.19.3 | 75 / 4 | |
| 7.19.1 | 75 / 4 | |
| 7.19.0 | 75 / 4 | |
| 7.18.10 | 75 / 4 | |
| 7.18.9 | 75 / 4 | |
| 7.18.6 | 75 / 4 | |
| 7.18.2 | 75 / 4 | |
| 7.18.0 | 75 / 4 | |
| 7.17.12 | 74 / 4 | |
| 7.17.10 | 74 / 4 | |
| 7.16.11 | 74 / 4 | |
| 7.16.10 | 74 / 4 | |
| 7.16.8 | 74 / 4 | |
| 7.16.7 | 74 / 4 | |
| 7.16.5 | 74 / 4 | |
| 7.16.4 | 74 / 3 | |
| 7.16.0 | 74 / 3 | |
| 7.15.8 | 73 / 3 | |
| 7.15.6 | 73 / 3 | |
| 7.15.4 | 73 / 4 | |
| 7.15.0 | 73 / 4 | |
| 7.14.9 | 73 / 4 | |
| 7.14.8 | 73 / 4 | |
| 7.14.7 | 73 / 4 | |
| 7.14.5 | 73 / 4 | |
| 7.14.4 | 73 / 4 | |
| 7.14.2 | 73 / 4 | |
| 7.14.1 | 73 / 4 | |
| 7.14.0 | 73 / 4 | |
| 7.13.15 | 69 / 4 | |
| 7.13.12 | 69 / 4 | |
| 7.13.10 | 68 / 4 | |
| 7.13.9 | 68 / 4 | |
| 7.13.8 | 68 / 3 | |
| 7.13.5 | 68 / 3 | |
| 7.13.0 | 68 / 3 | |
| 7.12.17 | 66 / 3 | |
| 7.12.16 | 66 / 3 | |
| 7.12.13 | 66 / 3 | |
| 7.12.11 | 66 / 3 | |
| 7.12.10 | 66 / 3 | |
| 7.12.7 | 66 / 3 | |
| 7.12.1 | 66 / 3 | |
| 7.12.0 | 67 / 5 | |
| 7.11.5 | 68 / 5 | |
| 7.11.0 | 68 / 5 | |
| 7.10.4 | 64 / 5 |
v7.29.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.29.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.29.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.29.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.18.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.