handlebars-path
Handlebars helper mappings for the node.js path module
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Package is 12 years old with a well-established publisher (75lb, 1486 approved packages). The 0.0.0 version is a legitimate initial release, not a malicious throwaway. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Tiny single-file helper wrapping Node.js path module; no deps is expected by design. Not spam — legitimate utility with a real GitHub repo and established publisher. | ai |
v1.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.