← Home

babel-template

Generate an AST from a string template.

26
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

thejameskylesebmckdanezhzoologanfsmyth

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Lack of Sigstore provenance is common (88% of npm) and not a material risk for an established Babel core library with 3827 days of history. ai
provenance publisher-changed AI (provenance): Historical Babel team transition (sebmck→amasad) from 2015; both are known Babel core contributors. Stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): hzoo and loganfsmyth are well-known Babel core team members; addition is a legitimate historical team expansion. ai
bogus-package bogus-package AI (bogus-package): Signals reflect legitimate Babel ecosystem structure (maintainer owns many Babel packages); not indicative of spam or malware for this core library. ai
dependencies unvetted-dep:babel-traverse AI (dependencies): babel-traverse is a core Babel dependency; unvetted status is expected for ecosystem-internal packages with long approval history. ai

Versions (showing 26 of 26)

Version Deps Published
6.26.0 5 / 0
6.25.0 5 / 0
6.24.1 5 / 0
6.23.0 5 / 0
6.22.0 5 / 0
6.16.0 5 / 0
6.15.0 5 / 0
6.14.0 5 / 0
6.9.0 5 / 0
6.8.0 5 / 0
6.7.0 5 / 0
6.6.5 5 / 0
6.6.4 5 / 0
6.6.0 5 / 0
6.5.0 5 / 0
6.3.13 5 / 0
6.3.0 5 / 0
6.2.4 5 / 0
6.2.0 5 / 0
6.1.18 5 / 0
6.1.17 5 / 0
6.0.16 5 / 0
6.0.15 5 / 0
6.0.14 5 / 0
6.0.12 5 / 0
6.0.2 5 / 0