← Home

@boost/log

Lightweight level based logging system.

48
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

milesj

Keywords

boostlogloggerlogginglevels

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Size increase from v1.x to v2.x reflects a major version rewrite of the boost monorepo. No obfuscation or payload indicators present; growth is consistent with added functionality. ai
publish-pattern new-deps-added AI (publish-pattern): @boost/common is a first-party dependency in the same milesj/boost monorepo. New @boost/* deps from the same publisher are expected as the monorepo evolves and are not a supply-chain risk. ai
provenance no-provenance AI (provenance): Established package from trusted publisher milesj; lack of Sigstore provenance is a known accepted risk for this package. ai
typosquat typosquat.levenshtein:got AI (typosquat): @boost/log is a scoped package in the @boost monorepo; Levenshtein proximity to 'got' is coincidental and not a typosquat. ai
typosquat typosquat.levenshtein:pg AI (typosquat): @boost/log is a scoped package in the @boost monorepo; Levenshtein proximity to 'pg' is coincidental and not a typosquat. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @boost/log is a scoped package in the @boost monorepo; Levenshtein proximity to 'joi' is coincidental and not a typosquat. ai
typosquat typosquat.levenshtein:zod AI (typosquat): @boost/log is a scoped package in the @boost monorepo; Levenshtein proximity to 'zod' is coincidental and not a typosquat. ai
dependencies unvetted-dep:@boost/internal AI (dependencies): @boost/internal is a sibling package in the same @boost monorepo by the same publisher (milesj); expected internal dependency. ai
dependencies unvetted-dep:@boost/translate AI (dependencies): @boost/translate is a sibling package in the same @boost monorepo by the same publisher (milesj); expected internal dependency. ai
typosquat typosquat.levenshtein:koa AI (typosquat): @boost/log is a scoped package in the @boost monorepo; Levenshtein proximity to 'koa' is coincidental and not a typosquat. ai
typosquat typosquat.levenshtein:glob AI (typosquat): @boost/log is a scoped package in the @boost monorepo; Levenshtein proximity to 'glob' is coincidental and not a typosquat. ai

Versions (showing 48 of 48)

Version Deps Published
5.0.0 4 / 0
4.0.1 4 / 0
4.0.0 4 / 0
3.0.3 4 / 0
3.0.2 4 / 0
3.0.1 4 / 0
3.0.0 4 / 0
2.2.8 4 / 0
2.2.7 4 / 0
2.2.6 4 / 0
2.2.5 4 / 0
2.2.4 4 / 0
2.2.3 4 / 0
2.2.2 4 / 0
2.2.1 4 / 0
2.2.0 4 / 0
2.1.8 4 / 0
2.1.7 4 / 0
2.1.6 4 / 0
2.1.5 4 / 0
2.1.4 4 / 0
2.1.3 4 / 0
2.1.2 4 / 0
2.1.1 4 / 0
2.1.0 4 / 0
2.0.1 4 / 0
2.0.0 4 / 0
1.2.1 3 / 0
1.2.0 3 / 0
1.1.14 3 / 0
1.1.13 3 / 0
1.1.12 3 / 0
1.1.11 3 / 0
1.1.10 3 / 0
1.1.9 3 / 0
1.1.8 3 / 0
1.1.7 3 / 0
1.1.6 3 / 0
1.1.5 3 / 0
1.1.4 3 / 0
1.1.3 3 / 0
1.1.2 3 / 0
1.1.1 3 / 0
1.1.0 3 / 0
1.0.3 3 / 0
1.0.2 3 / 0
1.0.1 3 / 0
1.0.0 3 / 0