esnextguardian
Load your ES6+ files if the user's environment supports it, otherwise gracefully fallback to your ES5 files.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): benjamin lupton and balupton are the same person (Benjamin Lupton); the GitHub handle in package.json is balupton. This is a username consolidation, not a hostile takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): balupton is the same individual as benjamin lupton — same person, different npm username. Not a new party gaining access. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): benjamin lupton was replaced by balupton, the same individual's canonical npm account. No actual maintainer loss. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is the core mechanism of esnextguardian — it conditionally loads ESNext or ES5 paths by design. This is a stable false positive for this package. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 1.2.1 | 0 / 6 | |
| 1.2.0 | 0 / 5 | |
| 1.1.0 | 0 / 6 | |
| 1.0.2 | 0 / 6 | |
| 1.0.1 | 0 / 1 | |
| 1.0.0 | 0 / 1 |
v1.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
2 findingsAll previous maintainers (benjamin lupton) were replaced by new maintainers (balupton). This is a strong signal of a potential package hijack and requires careful review.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.