@esbuild/android-arm64
The Android ARM 64-bit binary for esbuild, a JavaScript bundler.
12
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
esbuild
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): esbuild migrated to GitHub Actions CI/CD publishing; SLSA provenance attestation confirms builds originate from the official evanw/esbuild repo. This transition is stable for all future versions. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): evanw's removal as direct npm maintainer reflects the shift to automated GitHub Actions publishing, not a hostile takeover. SLSA attestation anchors trust to the source repo. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Bundled binary is the sole purpose of this platform-specific esbuild package; SLSA provenance provides integrity assurance. | ai | |
| bogus-package | bogus-package | AI (bogus-package): All esbuild platform packages share these structural characteristics (no deps, minimal README, no keywords) by design — not spam indicators. | ai |
Versions (showing 12 of 112)
| Version | Deps | Published |
|---|---|---|
| 0.16.9 | 0 / 0 | |
| 0.16.8 | 0 / 0 | |
| 0.16.7 | 0 / 0 | |
| 0.16.6 | 0 / 0 | |
| 0.16.5 | 0 / 0 | |
| 0.16.4 | 0 / 0 | |
| 0.16.3 | 0 / 0 | |
| 0.16.2 | 0 / 0 | |
| 0.16.1 | 0 / 0 | |
| 0.16.0 | 0 / 0 | |
| 0.15.18 | 0 / 0 | |
| 0.0.1-ignorepls | 0 / 0 |
v0.0.1-ignorepls
2 findings
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
INFO
Publisher changed: evanw → GitHub Actions (on 2025-11-02)
provenance
[Accepted risk] This version was published by a different npm account than previous versions on 2025-11-02. This could indicate a legitimate maintainer transition or an account compromise.