← Home

depcheck-es6

Check dependencies in your node module

9
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

lijunlerumpl

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): The dynamic require loads package.json from a user-supplied rootDir — this is core functionality for a dependency-checking tool, not an arbitrary module loading risk. ai
phantom-deps phantom-dep:optimist AI (phantom-deps): optimist is a CLI dependency referenced in config/scripts; not a security concern for this utility package. ai
publish-pattern new-deps-added AI (publish-pattern): The added 'request' dependency is a well-known HTTP client consistent with the new web-report feature introduced in this version. No malicious indicators. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance by years; absence of attestation is expected for this legacy package and not a risk signal. ai
dependencies unvetted-dep:request AI (dependencies): The `request` package is a well-known HTTP library used for the web-report feature; its presence is consistent with the package's documented functionality. ai
bogus-package bogus-package AI (bogus-package): Package is 3869 days old with a clear purpose and GitHub repo; README quality signals are cosmetic and not indicative of spam or malicious intent. ai

Versions (showing 9 of 9)

Version Deps Published
0.5.59 9 / 8
0.5.8 9 / 8
0.5.7 11 / 8
0.5.6 10 / 8
0.5.5 9 / 8
0.5.3 8 / 8
0.5.2 6 / 5
0.5.1 6 / 5
0.5.0 6 / 2

v0.5.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.