compress-buffer
Synchronous Buffer compression library for Node.js
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Native addon wrapper; no keywords/deps and a thin JS shim are expected patterns for this package type, not spam indicators. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): The added 'bindings' dependency is the canonical native addon loader utility; its addition is consistent with this package's native addon architecture. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Native addon package; bundled binaries are expected build artifacts from the C++ compression binding. | ai | |
| install-scripts | install-script:install | AI (install-scripts): node-gyp rebuild is the standard build step for this native C++ compression addon; stable and expected for this package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is used to load the compiled native .node binary from two standard build output paths — a well-known fallback pattern for native addons. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 1.2.1 | 0 / 1 | |
| 1.2.0 | 0 / 1 | |
| 1.0.0 | 0 / 1 | |
| 0.4.0 | 0 / 1 | |
| 0.3.1 | 0 / 0 |
v1.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.