← Home

@webassemblyjs/wasm-parser

WebAssembly binary format parser

67
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

xtuc

Keywords

webassemblyjavascriptastparserwasm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@xtuc/buffer AI (dependencies): @xtuc/buffer is published by the same author (xtuc) as this package; it's a Buffer polyfill appropriate for a binary format parser. Same-author scoped dep reduces supply-chain risk significantly. ai
dependencies unvetted-dep:@webassemblyjs/helper-leb128 AI (dependencies): Same-org sibling package within the @webassemblyjs monorepo; expected dependency, not a risk. ai
dependencies unvetted-dep:webassemblyjs AI (dependencies): webassemblyjs is the parent monorepo package from the same author (xtuc); this dependency is expected and benign for all versions of this package. ai
phantom-deps phantom-dep:@webassemblyjs/wasm-parser AI (phantom-deps): Package listing itself as a dependency is a monorepo artifact in this early version; not a security concern for this package. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance on npm by years; absence of provenance is expected and not a risk signal here. ai
dependencies unvetted-dep:@webassemblyjs/helper-api-error AI (dependencies): Part of the same @webassemblyjs monorepo published by the same trusted author (xtuc). Internal utility package with no independent risk. ai
dependencies unvetted-dep:@webassemblyjs/utf8 AI (dependencies): Part of the same @webassemblyjs monorepo published by the same trusted author (xtuc). Internal utility package with no independent risk. ai
dependencies unvetted-dep:@webassemblyjs/ieee754 AI (dependencies): Part of the same @webassemblyjs monorepo published by the same trusted author (xtuc). Internal utility package with no independent risk. ai
dependencies unvetted-dep:@webassemblyjs/leb128 AI (dependencies): Part of the same @webassemblyjs monorepo published by the same trusted author (xtuc). Internal utility package with no independent risk. ai

Versions (showing 67 of 67)

Version Deps Published
1.14.1 6 / 7
1.13.2 6 / 7
1.13.1 6 / 7
1.12.1 6 / 7
1.11.6 6 / 7
1.11.5 6 / 7
1.11.3 6 / 7
1.11.1 6 / 7
1.11.0 6 / 7
1.10.1 6 / 7
1.10.0 6 / 7
1.9.1 6 / 7
1.9.0 6 / 7
1.8.5 6 / 6
1.8.4 6 / 6
1.8.3 6 / 6
1.8.2 6 / 6
1.8.1 6 / 6
1.8.0 6 / 6
1.7.11 6 / 5
1.7.10 6 / 6
1.7.9 6 / 5
1.7.8 6 / 5
1.7.7 6 / 6
1.7.6 6 / 6
1.7.5 6 / 6
1.7.4 7 / 6
1.7.3 7 / 6
1.7.2 7 / 6
1.7.1 6 / 6
1.7.0 6 / 6
1.6.1 6 / 6
1.6.0 6 / 6
1.5.13 6 / 6
1.5.12 6 / 6
1.5.11 6 / 7
1.5.10 6 / 7
1.5.9 6 / 6
1.5.8 5 / 6
1.5.7 5 / 6
1.5.6 5 / 6
1.5.5 5 / 3
1.5.4 5 / 3
1.5.3 5 / 3
1.5.2 5 / 3
1.5.1 5 / 3
1.5.0 5 / 3
1.4.3 5 / 3
1.4.2 5 / 3
1.4.1 5 / 3
1.4.0 5 / 3
1.3.3 5 / 3
1.3.2 5 / 3
1.3.1 5 / 3
1.3.0 5 / 3
1.2.8 5 / 3
1.2.7 5 / 3
1.2.6 5 / 2
1.2.5 5 / 2
1.2.4 5 / 2
1.2.3 5 / 2
1.2.2 5 / 0
1.2.1 5 / 0
1.2.0 5 / 0
1.1.1 5 / 0
1.1.0 5 / 0
1.0.0 3 / 0