@bundled-es-modules/glob
mirror of glob, bundled and exposed as ES module including for browser
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs patch-package, a declared dependency used to patch glob for browser compatibility — consistent with this package's documented bundling purpose across all versions. | ai | |
| phantom-deps | phantom-dep:url | AI (phantom-deps): Browser polyfill for Node.js built-in; declared in dependencies and used by the bundler/build process for browser compatibility. Not a phantom dep in this context. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Browser polyfill for Node.js built-in; declared in dependencies and used by the bundler/build process for browser compatibility. | ai | |
| phantom-deps | phantom-dep:events | AI (phantom-deps): Browser polyfill for Node.js built-in; declared in dependencies and used by the bundler/build process for browser compatibility. | ai | |
| phantom-deps | phantom-dep:stream | AI (phantom-deps): Browser polyfill for Node.js built-in; declared in dependencies and used by the bundler/build process for browser compatibility. | ai | |
| phantom-deps | phantom-dep:patch-package | AI (phantom-deps): patch-package is declared in dependencies and invoked via postinstall; the phantom-dep finding is a false positive for this usage pattern. | ai | |
| phantom-deps | phantom-dep:string_decoder | AI (phantom-deps): Browser polyfill for Node.js built-in; declared in dependencies and used by the bundler/build process for browser compatibility. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 13.0.6 | 7 / 5 | |
| 13.0.3 | 7 / 5 | |
| 13.0.1 | 7 / 5 | |
| 11.1.0 | 7 / 5 | |
| 11.0.3 | 7 / 5 | |
| 10.4.2 | 8 / 4 | |
| 10.3.13 | 8 / 4 | |
| 10.3.12 | 7 / 5 | |
| 10.3.11 | 7 / 5 | |
| 10.3.10 | 8 / 4 | |
| 10.3.5 | 8 / 4 | |
| 10.3.4 | 8 / 2 | |
| 10.3.3 | 7 / 3 |
v13.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.4.2
2 findingsScript: patch-package
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.