← Home

isparta

A code coverage tool for ES6 (babel)

30
Versions
WTFPL
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

douglasduteil

Keywords

karmakarma-coveragekarma-traceur-preprocessoristanbul6to5babeles6harmony

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:eval-usage AI (semgrep): All eval() findings are in node_modules_old/ (archived vendored deps, not active code). The specific instance is a known V8 optimization pattern in Babel internals. ai
semgrep semgrep:new-function-constructor AI (semgrep): new Function() usage is in node_modules_old/babel-core — archived vendored code, not active runtime code in the published package. ai
semgrep semgrep:child-process-import AI (semgrep): child_process imports are in node_modules_old/nodemon — archived vendored dev tooling, not active runtime code. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require(file) is intentional in a code coverage CLI tool — it loads user-specified files for instrumentation. This pattern is stable and expected for isparta. ai
dependencies unvetted-dep:babel-core AI (dependencies): babel-core is a core Babel transpiler package; its use is expected and appropriate for an ES6 code coverage tool like isparta. ai

Versions (showing 30 of 30)

Version Deps Published
4.1.1 9 / 10
4.1.0 9 / 10
4.0.0 9 / 11
3.5.3 10 / 5
3.5.2 10 / 5
3.5.1 10 / 5
3.5.0 10 / 5
3.4.0 10 / 5
3.3.0 10 / 5
3.2.0 10 / 5
3.1.0 10 / 5
2.2.0 9 / 6
2.1.0 9 / 6
2.0.0 9 / 5
1.4.2 9 / 5
1.4.1 9 / 5
1.4.0 9 / 5
1.3.0 9 / 5
1.2.0 8 / 3
1.1.0 8 / 2
1.0.1 8 / 3
1.0.0 8 / 3
0.4.1 8 / 3
0.4.0 8 / 3
0.3.1 8 / 3
0.3.0 8 / 3
0.2.0 8 / 2
0.1.2 7 / 7
0.1.1 7 / 7
0.1.0 7 / 7

v4.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.