← Home

cborg

Fast CBOR with a focus on strictness

19
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

rvagg

Keywords

cbor

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): Major version bump (v4→v5) with SLSA provenance from same repo. Dormancy is normal for stable libraries between majors. ai
source-diff encoded-string-file:test/test-3string.js AI (source-diff): CBOR hex test fixtures (string encoding tests). Stable false positive for a CBOR library. ai
source-diff encoded-string-file:test/test-5map.js AI (source-diff): CBOR hex test fixtures (map encoding tests). Stable false positive for a CBOR library. ai
provenance publisher-changed AI (provenance): Migration from manual publish to GitHub Actions CI/CD with SLSA provenance; same repo owner (rvagg). Stable for this package. ai
source-diff encoded-string-file:test/node-test-bin.js AI (source-diff): CBOR hex test fixtures in test files — core to a CBOR library's test suite. Stable false positive. ai
source-diff encoded-string-file:test/test-2bytes.js AI (source-diff): CBOR hex test fixtures (byte encoding tests). Stable false positive for a CBOR library. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decoding in example-json.js is benign example code demonstrating CBOR/JSON decode from a literal hex string. Standard documentation pattern for a binary serialization library. ai
typosquat typosquat.levenshtein:cors AI (typosquat): cborg is a deliberate CBOR library name (CBOR + org), not a typosquat of cors. These packages serve entirely different purposes; the Levenshtein match is a stable false positive. ai

Versions (showing 19 of 19)

Version Deps Published
5.1.1 0 / 18
5.1.0 0 / 18
5.0.1 0 / 18
5.0.0 0 / 18
4.5.8 0 / 18
4.5.7 0 / 18
4.5.6 0 / 18
4.5.5 0 / 18
4.5.4 0 / 18
4.5.3 0 / 18
4.5.2 0 / 18
4.5.1 0 / 18
4.5.0 0 / 18
4.4.1 0 / 18
4.4.0 0 / 18
4.3.2 0 / 18
4.3.1 0 / 18
4.3.0 0 / 18
4.2.13 0 / 18

v5.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.