depcheck-es6
Check dependencies in your node module
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): The dynamic require loads package.json from a user-supplied rootDir — this is core functionality for a dependency-checking tool, not an arbitrary module loading risk. | ai | |
| phantom-deps | phantom-dep:optimist | AI (phantom-deps): optimist is a CLI dependency referenced in config/scripts; not a security concern for this utility package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): The added 'request' dependency is a well-known HTTP client consistent with the new web-report feature introduced in this version. No malicious indicators. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance by years; absence of attestation is expected for this legacy package and not a risk signal. | ai | |
| dependencies | unvetted-dep:request | AI (dependencies): The `request` package is a well-known HTTP library used for the web-report feature; its presence is consistent with the package's documented functionality. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Package is 3869 days old with a clear purpose and GitHub repo; README quality signals are cosmetic and not indicative of spam or malicious intent. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 0.5.59 | 9 / 8 | |
| 0.5.8 | 9 / 8 | |
| 0.5.7 | 11 / 8 | |
| 0.5.6 | 10 / 8 | |
| 0.5.5 | 9 / 8 | |
| 0.5.3 | 8 / 8 | |
| 0.5.2 | 6 / 5 | |
| 0.5.1 | 6 / 5 | |
| 0.5.0 | 6 / 2 |
v0.5.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.