← Home

babel-helper-bindify-decorators

Helper function to bindify decorators

10
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amasadhzoojmmloganfsmythsebmckthejameskyle

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Legitimate Babel maintainer transition from sebmck to hzoo, both core Babel team members. Well-documented handoff. ai
maintainer-change maintainer-added AI (maintainer-change): hzoo, jmm, and loganfsmyth are well-known Babel core team members; this is a legitimate team expansion for the official Babel monorepo package. ai
bogus-package bogus-package AI (bogus-package): Legitimate Babel monorepo helper package; templated naming, no keywords, and tiny payload are all expected characteristics of this package family. ai
phantom-deps phantom-dep:babel-traverse AI (phantom-deps): babel-traverse is a legitimate declared dependency in this Babel helper; indirect usage via config is normal for Babel ecosystem packages. ai
dependencies unvetted-dep:babel-traverse AI (dependencies): babel-traverse is a core Babel ecosystem package; flagging it as unvetted is a stable false positive for any Babel helper package. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance by years; absence of attestation is expected and not a risk signal for this legacy Babel package. ai

Versions (showing 10 of 10)

Version Deps Published
6.24.1 3 / 0
6.18.0 3 / 0
6.6.4 3 / 0
6.6.0 3 / 0
6.5.0 3 / 0
6.3.13 3 / 0
6.1.17 3 / 0
6.1.15 3 / 0
6.1.8 3 / 0
6.1.5 3 / 0

v6.24.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.0

2 findings
HIGH Publisher changed: sebmck → hzoo (on 2016-02-29) provenance

This version was published by a different npm account than previous versions on 2016-02-29. This could indicate a legitimate maintainer transition or an account compromise.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.0

2 findings
HIGH Publisher changed: sebmck → hzoo (on 2016-02-07) provenance

This version was published by a different npm account than previous versions on 2016-02-07. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.