← Home

babel-types

Babel Types is a Lodash-esque utility library for AST nodes

56
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

thejameskylesebmckdanezhzoologanfsmyth

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): The sebmck→amasad transition in Dec 2015 is a documented, legitimate Babel maintainer handoff. amasad is a known Babel contributor; this generalizes across all babel-types versions. ai
maintainer-change maintainer-added AI (maintainer-change): hzoo, jmm, and loganfsmyth are well-known Babel core team members added during the legitimate Dec 2015 team expansion. Stable for this package. ai
provenance no-provenance AI (provenance): babel-types v6.x was published in 2015, well before Sigstore provenance was available on npm. No provenance is expected for this era of packages. ai
bogus-package bogus-package AI (bogus-package): babel-types is a legitimate core Babel package. The mass-production signal reflects the Babel monorepo's many similarly-named packages, not spam. Missing keywords is trivial. ai
dependencies unvetted-dep:to-fast-properties AI (dependencies): to-fast-properties is a well-known V8 optimization utility used throughout the Babel 6.x ecosystem. Not a risk. ai
dependencies unvetted-dep:esutils AI (dependencies): esutils is a well-known, legitimate JS ecosystem utility used across many AST tools. Not a risk for this package. ai
dependencies unvetted-dep:babel-runtime AI (dependencies): babel-runtime is a core Babel package from the same monorepo. Not a risk. ai

Versions (showing 56 of 56)

Version Deps Published
6.26.0 4 / 2
6.25.0 4 / 1
6.24.1 4 / 1
6.23.0 4 / 1
6.22.0 4 / 1
6.21.0 4 / 1
6.20.0 4 / 1
6.19.0 4 / 1
6.18.0 4 / 0
6.16.0 4 / 0
6.15.0 4 / 0
6.14.0 5 / 0
6.13.0 5 / 0
6.11.1 5 / 0
6.10.2 5 / 0
6.10.0 5 / 0
6.9.1 5 / 0
6.9.0 5 / 0
6.8.1 5 / 0
6.8.0 5 / 0
6.7.7 5 / 0
6.7.2 5 / 0
6.7.0 5 / 0
6.6.5 5 / 0
6.6.4 5 / 0
6.6.0 5 / 0
6.5.2 5 / 0
6.5.1 5 / 0
6.5.0 5 / 0
6.4.5 5 / 0
6.4.3 5 / 0
6.4.1 5 / 0
6.4.0 5 / 0
6.3.24 5 / 0
6.3.21 5 / 0
6.3.20 5 / 0
6.3.18 5 / 0
6.3.17 5 / 0
6.3.14 5 / 0
6.3.13 5 / 0
6.3.0 5 / 0
6.2.4 5 / 0
6.2.3 5 / 0
6.2.0 5 / 0
6.1.18 5 / 0
6.1.17 5 / 0
6.1.4 5 / 0
6.1.2 5 / 0
6.0.19 5 / 0
6.0.18 5 / 0
6.0.17 5 / 0
6.0.15 5 / 0
6.0.14 5 / 0
6.0.13 5 / 0
6.0.12 5 / 0
6.0.2 5 / 0

v6.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.