← Home

jszip

Create, read and edit .zip files with JavaScript http://stuartk.com/jszip

1
Versions
(MIT OR GPL-3.0-or-later)
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

dduponchelcwmmastuk

Keywords

zipdeflateinflate

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:lie AI (dependencies): lie is a well-known Promise polyfill; a stable, legitimate dependency of JSZip across multiple versions. ai
dependencies unvetted-dep:pako AI (dependencies): pako is a widely-used zlib/deflate port; a core, legitimate dependency of JSZip for compression support. ai
dependencies unvetted-dep:setimmediate AI (dependencies): setimmediate is a well-known async polyfill; a stable, legitimate dependency of JSZip. ai

Versions (showing 1 of 1)

Version Deps Published
3.10.1 4 / 14