flow-bin
Binary wrapper for Flow - A static type checker for JavaScript
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): flow-bin's purpose is to ship prebuilt Flow binaries for linux64/osx/win64; bundled binaries are expected and include SHASUM256 verification. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): flow-bin is a binary wrapper; postinstall downloads prebuilt Flow binaries. Standard pattern for *-bin packages, stable across versions. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): flow-bin is a binary wrapper whose entire purpose is to spawn the Flow executable via child_process.spawn. This pattern is stable and expected across all versions of this package. | ai |
Versions (showing 100 of 386)
| Version | Deps | Published |
|---|---|---|
| 0.278.0 | 0 / 0 | |
| 0.277.1 | 0 / 0 | |
| 0.276.0 | 0 / 0 | |
| 0.275.0 | 0 / 0 | |
| 0.274.2 | 0 / 0 | |
| 0.274.1 | 0 / 0 | |
| 0.274.0 | 0 / 0 | |
| 0.273.1 | 0 / 0 | |
| 0.272.2 | 0 / 0 | |
| 0.272.1 | 0 / 0 | |
| 0.272.0 | 0 / 0 | |
| 0.271.0 | 0 / 0 | |
| 0.270.0 | 0 / 0 | |
| 0.269.1 | 0 / 0 | |
| 0.268.0 | 0 / 0 | |
| 0.267.0 | 0 / 0 | |
| 0.266.1 | 0 / 0 | |
| 0.266.0 | 0 / 0 | |
| 0.265.3 | 0 / 0 | |
| 0.265.2 | 0 / 0 | |
| 0.265.1 | 0 / 0 | |
| 0.265.0 | 0 / 0 | |
| 0.264.0 | 0 / 0 | |
| 0.263.0 | 0 / 0 | |
| 0.262.0 | 0 / 0 | |
| 0.261.2 | 0 / 0 | |
| 0.261.1 | 0 / 0 | |
| 0.261.0 | 0 / 0 | |
| 0.260.0 | 0 / 0 | |
| 0.259.1 | 0 / 0 | |
| 0.259.0 | 0 / 0 | |
| 0.258.1 | 0 / 0 | |
| 0.258.0 | 0 / 0 | |
| 0.257.1 | 0 / 0 | |
| 0.257.0 | 0 / 0 | |
| 0.256.0 | 0 / 0 | |
| 0.255.0 | 0 / 0 | |
| 0.254.2 | 0 / 0 | |
| 0.254.1 | 0 / 0 | |
| 0.254.0 | 0 / 0 | |
| 0.253.0 | 0 / 0 | |
| 0.252.0 | 0 / 0 | |
| 0.251.1 | 0 / 0 | |
| 0.251.0 | 0 / 0 | |
| 0.250.0 | 0 / 0 | |
| 0.249.0 | 0 / 0 | |
| 0.248.1 | 0 / 0 | |
| 0.248.0 | 0 / 0 | |
| 0.247.1 | 0 / 0 | |
| 0.247.0 | 0 / 0 | |
| 0.246.0 | 0 / 0 | |
| 0.245.2 | 0 / 0 | |
| 0.245.1 | 0 / 0 | |
| 0.245.0 | 0 / 0 | |
| 0.244.0 | 0 / 0 | |
| 0.243.0 | 0 / 0 | |
| 0.242.1 | 0 / 0 | |
| 0.242.0 | 0 / 0 | |
| 0.241.0 | 0 / 0 | |
| 0.240.0 | 0 / 0 | |
| 0.239.1 | 0 / 0 | |
| 0.239.0 | 0 / 0 | |
| 0.238.3 | 0 / 0 | |
| 0.238.2 | 0 / 0 | |
| 0.238.1 | 0 / 0 | |
| 0.238.0 | 0 / 0 | |
| 0.237.2 | 0 / 0 | |
| 0.237.1 | 0 / 0 | |
| 0.237.0 | 0 / 0 | |
| 0.236.0 | 0 / 0 | |
| 0.235.1 | 0 / 0 | |
| 0.234.0 | 0 / 0 | |
| 0.233.0 | 0 / 0 | |
| 0.232.0 | 0 / 0 | |
| 0.231.0 | 0 / 0 | |
| 0.230.0 | 0 / 0 | |
| 0.229.2 | 0 / 0 | |
| 0.229.0 | 0 / 0 | |
| 0.228.0 | 0 / 0 | |
| 0.227.0 | 0 / 0 | |
| 0.226.0 | 0 / 0 | |
| 0.225.1 | 0 / 0 | |
| 0.225.0 | 0 / 0 | |
| 0.224.0 | 0 / 0 | |
| 0.223.3 | 0 / 0 | |
| 0.223.2 | 0 / 0 | |
| 0.223.0 | 0 / 0 | |
| 0.222.0 | 0 / 0 | |
| 0.221.0 | 0 / 0 | |
| 0.220.1 | 0 / 0 | |
| 0.220.0 | 0 / 0 | |
| 0.219.5 | 0 / 0 | |
| 0.219.4 | 0 / 0 | |
| 0.219.3 | 0 / 0 | |
| 0.219.2 | 0 / 0 | |
| 0.219.0 | 0 / 0 | |
| 0.218.1 | 0 / 0 | |
| 0.218.0 | 0 / 0 | |
| 0.217.2 | 0 / 0 | |
| 0.217.1 | 0 / 0 |
v0.278.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.277.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.276.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.275.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.274.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.274.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.274.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.273.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.272.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.272.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.272.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.271.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.270.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.269.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.268.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.267.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.266.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.266.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.265.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.265.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.265.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.265.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.264.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.263.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.262.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.261.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.261.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.261.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.260.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.259.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.259.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.258.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.258.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.257.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.257.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.256.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.255.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.254.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.254.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.254.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.253.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.252.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.251.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.251.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.250.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.249.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.248.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.248.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.247.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.247.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.246.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.245.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.245.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.245.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.244.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.243.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.242.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.242.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.241.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.240.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.239.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.239.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.238.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.238.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.238.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.238.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.237.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.237.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.237.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.236.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.235.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.234.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.233.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.232.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.231.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.230.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.229.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.229.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.228.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.227.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.226.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.225.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.225.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.224.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.223.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.223.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.223.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.222.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.221.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.220.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.220.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.219.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.219.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.219.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.219.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.219.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.218.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.218.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.217.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.217.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.