← Home

babel-helper-explode-assignable-expression

Helper function to explode an assignable expression

13
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

amasadhzoojmmloganfsmythsebmckthejameskyle

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): amasad and thejameskyle are well-known Babel core team members; their addition is a legitimate and expected team expansion for this official Babel package. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance by years; absence of attestation is expected for this era of Babel tooling and not a security signal. ai
dependencies unvetted-dep:babel-traverse AI (dependencies): babel-traverse is a canonical Babel core package; flagging it as unvetted is a stable false positive for any Babel helper package. ai
bogus-package bogus-package AI (bogus-package): Legitimate Babel 6.x monorepo helper package. Spam-flagged publishers are Babel core contributors; tiny payload and no keywords are expected for internal Babel helpers. ai
phantom-deps phantom-dep:babel-runtime AI (phantom-deps): babel-runtime is a standard Babel 6.x runtime dependency used via transform config, not direct import. Expected pattern for this package. ai
phantom-deps phantom-dep:babel-traverse AI (phantom-deps): babel-traverse is used transitively in Babel 6.x helper packages; phantom-dep detection is a false positive for this ecosystem pattern. ai

Versions (showing 13 of 13)

Version Deps Published
6.24.1 3 / 0
6.6.5 3 / 0
6.1.16 3 / 0
6.1.13 3 / 0
6.1.12 3 / 0
6.1.11 3 / 0
6.1.9 3 / 0
6.1.8 3 / 0
6.1.7 3 / 0
6.1.6 3 / 0
6.1.5 3 / 0
6.0.15 3 / 0
6.0.14 3 / 0

v6.24.1

2 findings
HIGH Low-value / spam package indicators (4 signals, score 8) bogus-package

Matched 4 signal(s), weighted score 8: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: sebmck, amasad, thejameskyle, jmm, hzoo, loganfsmyth. • [S_PUBLISHER_MASS_PRODUCTION] Maintainer 'loganfsmyth' owns 167 packages, ≥70% share a templated name shape. • [S_NO_KEYWORDS] No keywords declared. • [S_TINY_PAYLOAD] Tiny payload: 1 code file(s), 2495 bytes total.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.