get-intrinsic
Get and robustly cache all JS language-level intrinsics at first require time
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Mature stable library; long dormancy followed by release is normal for established packages. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are legitimate intrinsic detection enhancements from trusted publisher, not suspicious third-party additions. | ai | |
| dependencies | unvetted-dep:has | AI (dependencies): has is a well-known, widely-used npm utility package with a long history; its use here by ljharb is expected and low-risk across all versions of get-intrinsic. | ai | |
| provenance | no-provenance | AI (provenance): Provenance is a nice-to-have; ljharb's long history and established reputation mitigate the lack of Sigstore attestation. | ai | |
| dependencies | unvetted-dep:async-generator-function | AI (dependencies): async-generator-function is a legitimate ljharb-maintained utility package; unvetted flag is a false positive for this well-known ecosystem. | ai | |
| dependencies | unvetted-dep:async-function | AI (dependencies): New dep from trusted publisher ljharb; aligns with package's intrinsic detection purpose. | ai | |
| dependencies | unvetted-dep:get-proto | AI (dependencies): get-proto is a focused utility; ljharb's track record and version constraint ^1.0.1 are sufficient. | ai | |
| dependencies | unvetted-dep:gopd | AI (dependencies): gopd is a focused utility from the same ecosystem; ljharb's track record and version constraint ^1.2.0 are sufficient. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 1.3.1 | 13 / 18 | |
| 1.3.0 | 10 / 18 | |
| 1.2.7 | 10 / 18 | |
| 1.2.6 | 10 / 18 | |
| 1.2.5 | 8 / 18 | |
| 1.2.1 | 4 / 19 | |
| 1.2.0 | 3 / 19 | |
| 1.1.3 | 3 / 18 | |
| 1.1.2 | 3 / 18 | |
| 1.1.1 | 3 / 16 | |
| 1.1.0 | 3 / 15 | |
| 1.0.2 | 3 / 14 | |
| 1.0.1 | 3 / 14 | |
| 1.0.0 | 0 / 13 |
v1.2.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.