← Home

@speed-highlight/core

7
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

matubu

Keywords

javascriptsyntax-highlightinglanguagefastjssimplehighlighterregexhighlightinghighlightjssmalldeno

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed from matubu to GitHub Actions as part of a deliberate CI/CD migration; SLSA provenance attestation confirms the publish originates from the correct GitHub repo. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by GitHub Actions publish is consistent with a CI/CD pipeline migration, not account takeover; SLSA provenance corroborates legitimacy. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped package @speed-highlight/core is a 4+ year old syntax highlighter; 'core' is its own module name, not an impersonation of 'cors'. False positive for this package. ai

Versions (showing 7 of 7)

Version Deps Published
1.2.15 0 / 5
1.2.14 0 / 5
1.2.12 0 / 5
1.2.11 0 / 5
1.2.10 0 / 5
1.2.9 0 / 5
1.2.8 0 / 5

v1.2.15

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'cors' typosquat

Package name '@speed-highlight/core' is 1 edit(s) away from popular package 'cors'.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.