@boost/config
Powerful convention based finder, loader, and manager of both configuration and ignore files.
32
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
milesj
Keywords
boostconfigconfigurationloader
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Lack of provenance is common across npm (~88% of packages); not a disqualifier for established publishers with strong track records. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @boost/event is from same monorepo; new dependency is expected for config library evolution. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 28 new source files in mature package with no other signals; reflects normal development, not injected code. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require for ES module loading is a legitimate pattern in this context; no arbitrary code execution risk. | ai | |
| dependencies | unvetted-dep:@boost/internal | AI (dependencies): Internal @boost dependency; part of the same monorepo ecosystem managed by the same publisher. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 5.0.0 | 6 / 1 | |
| 4.0.1 | 6 / 1 | |
| 4.0.0 | 6 / 1 | |
| 3.2.0 | 6 / 1 | |
| 3.1.0 | 6 / 1 | |
| 3.0.4 | 6 / 1 | |
| 3.0.3 | 6 / 1 | |
| 3.0.2 | 6 / 1 | |
| 3.0.1 | 6 / 1 | |
| 3.0.0 | 6 / 1 | |
| 2.5.2 | 5 / 1 | |
| 2.5.1 | 5 / 1 | |
| 2.5.0 | 5 / 1 | |
| 2.4.2 | 5 / 1 | |
| 2.4.1 | 5 / 1 | |
| 2.4.0 | 5 / 1 | |
| 2.3.3 | 5 / 1 | |
| 2.3.2 | 5 / 1 | |
| 2.3.1 | 5 / 1 | |
| 2.3.0 | 5 / 1 | |
| 2.2.8 | 5 / 1 | |
| 2.2.7 | 5 / 1 | |
| 2.2.6 | 5 / 1 | |
| 2.2.5 | 5 / 1 | |
| 2.2.4 | 5 / 1 | |
| 2.2.3 | 5 / 1 | |
| 2.2.2 | 5 / 1 | |
| 2.2.1 | 5 / 1 | |
| 2.2.0 | 5 / 1 | |
| 2.1.0 | 5 / 1 | |
| 2.0.0 | 4 / 1 | |
| 1.0.0 | 4 / 1 |