@rspack/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in vendored browserslist loads caniuse-lite region data by validated region code — standard browserslist behavior, not arbitrary module loading. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval("require") in vendored browserslist is a standard bundler idiom to prevent static require analysis, not an attack vector. Stable false positive for this package. | ai | |
| source-diff | encoded-string-file:dist/worker.js | AI (source-diff): Same WASM xxhash64 module embedded in worker bundle — identical legitimate pattern as in dist/index.js, stable across rspack versions. | ai | |
| source-diff | encoded-string-file:dist/index.js | AI (source-diff): Encoded strings are base64-encoded WebAssembly modules for xxhash64 hashing — a legitimate, documented pattern for rspack's bundled WASM hash implementation. | ai | |
| phantom-deps | phantom-dep:@tmp-sass-embedded/darwin-x64 | AI (phantom-deps): Platform-specific optional binary for sass-embedded; declared in optionalDependencies and loaded conditionally. Legitimate pattern. | ai | |
| phantom-deps | phantom-dep:@tmp-sass-embedded/win32-ia32 | AI (phantom-deps): Platform-specific optional binary for sass-embedded; declared in optionalDependencies and loaded conditionally. Legitimate pattern. | ai | |
| phantom-deps | phantom-dep:@tmp-sass-embedded/linux-arm64 | AI (phantom-deps): Platform-specific optional binary for sass-embedded; declared in optionalDependencies and loaded conditionally. Legitimate pattern. | ai | |
| phantom-deps | phantom-dep:@tmp-sass-embedded/darwin-arm64 | AI (phantom-deps): Platform-specific optional binary for sass-embedded; declared in optionalDependencies and loaded conditionally. Legitimate pattern. | ai | |
| phantom-deps | phantom-dep:@rspack/dev-client | AI (phantom-deps): Same-org dependency declared in runtime deps; conditionally loaded. Not a phantom dep in the malicious sense. | ai | |
| phantom-deps | phantom-dep:@tmp-sass-embedded/linux-ia32 | AI (phantom-deps): Platform-specific optional binary for sass-embedded; declared in optionalDependencies and loaded conditionally. Legitimate pattern. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @rspack/core is a well-known Rust-based bundler under the @rspack scope; no impersonation of 'cors'. This is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tmp-sass-embedded/linux-x64 | AI (phantom-deps): Platform-specific optional binary for sass-embedded; declared in optionalDependencies and loaded conditionally. Legitimate pattern. | ai | |
| phantom-deps | phantom-dep:@tmp-sass-embedded/win32-x64 | AI (phantom-deps): Platform-specific optional binary for sass-embedded; declared in optionalDependencies and loaded conditionally. Legitimate pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): hardfist (Boshen Chen) is the well-known creator of Rspack/Oxc; spam flag is a false positive. No-keywords signal is irrelevant for a major bundler package. | ai |
Versions (showing 51 of 180)
| Version | Deps | Published |
|---|---|---|
| 2.0.5 | 1 / 19 | |
| 2.0.4 | 1 / 19 | |
| 2.0.3 | 1 / 19 | |
| 2.0.2 | 1 / 19 | |
| 2.0.1 | 1 / 20 | |
| 2.0.0 | 1 / 20 | |
| 1.7.11 | 3 / 17 | |
| 1.7.10 | 3 / 17 | |
| 1.7.9 | 3 / 17 | |
| 1.7.8 | 3 / 17 | |
| 1.7.7 | 3 / 17 | |
| 1.7.6 | 3 / 17 | |
| 1.7.5 | 3 / 17 | |
| 1.7.4 | 3 / 17 | |
| 1.7.3 | 3 / 17 | |
| 1.7.2 | 3 / 17 | |
| 1.7.1 | 3 / 17 | |
| 1.7.0 | 3 / 17 | |
| 1.6.8 | 3 / 17 | |
| 1.6.7 | 3 / 17 | |
| 1.6.6 | 3 / 17 | |
| 1.6.5 | 3 / 17 | |
| 1.6.4 | 3 / 17 | |
| 1.6.3 | 3 / 17 | |
| 1.6.2 | 3 / 17 | |
| 1.6.1 | 3 / 17 | |
| 1.6.0 | 3 / 17 | |
| 1.5.8 | 3 / 19 | |
| 1.5.7 | 3 / 19 | |
| 1.5.6 | 3 / 19 | |
| 1.5.5 | 3 / 19 | |
| 1.5.4 | 3 / 19 | |
| 1.5.3 | 3 / 19 | |
| 1.5.2 | 3 / 19 | |
| 1.5.1 | 3 / 19 | |
| 1.5.0 | 3 / 19 | |
| 1.4.11 | 3 / 18 | |
| 1.4.10 | 3 / 19 | |
| 1.4.9 | 3 / 19 | |
| 1.4.8 | 3 / 19 | |
| 1.4.7 | 3 / 19 | |
| 1.4.6 | 3 / 17 | |
| 1.4.5 | 3 / 18 | |
| 1.4.4 | 3 / 17 | |
| 1.4.3 | 3 / 17 | |
| 1.4.2 | 3 / 16 | |
| 1.4.1 | 3 / 16 | |
| 1.4.0 | 3 / 16 | |
| 1.3.15 | 3 / 16 | |
| 1.3.14 | 3 / 16 | |
| 1.3.13 | 3 / 16 |
v2.0.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.11
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.10
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.9
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.8
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.7
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.6
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.5
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.4
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.3
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.2
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.1
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.0
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.8
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.7
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.6
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.5
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.4
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.3
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.2
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.1
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.0
3 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.