backport
A CLI tool that automates the process of backporting commits
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:dedent | AI (phantom-deps): dedent is a declared runtime dep used via config/codegen tooling; stable false positive. | ai | |
| phantom-deps | phantom-dep:graphql-tag | AI (phantom-deps): graphql-tag declared as runtime dep, used via codegen config; stable false positive. | ai | |
| phantom-deps | phantom-dep:safe-json-stringify | AI (phantom-deps): safe-json-stringify declared as runtime dep; stable false positive. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Guarded postinstall only runs a local dist script if present; benign pattern stable across versions. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv is a declared runtime dependency used via config files; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 12.0.0 | 18 / 27 | |
| 11.0.2 | 18 / 27 | |
| 11.0.1 | 18 / 27 | |
| 11.0.0 | 18 / 27 | |
| 10.4.0 | 22 / 34 |
v12.0.0
2 findingsScript: test -f ./dist/src/scripts/run-postinstall.js && node ./dist/src/scripts/run-postinstall.js || echo 'Dist folder missing'
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.0.2
2 findingsScript: test -f ./dist/src/scripts/run-postinstall.js && node ./dist/src/scripts/run-postinstall.js || echo 'Dist folder missing'
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.0.1
2 findingsScript: test -f ./dist/src/scripts/run-postinstall.js && node ./dist/src/scripts/run-postinstall.js || echo 'Dist folder missing'
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.0.0
2 findingsScript: test -f ./dist/src/scripts/run-postinstall.js && node ./dist/src/scripts/run-postinstall.js || echo 'Dist folder missing'
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.4.0
2 findingsScript: test -f ./dist/src/scripts/run-postinstall.js && node ./dist/src/scripts/run-postinstall.js || echo 'Dist folder missing'
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.