klor
syntax highlighting
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): The dynamic require loads a bundled local JSON file via a fixed relative path (__dirname + '/../js/lang.json'). Not arbitrary module loading; stable false positive for this package. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() is used to reference color functions by name from a controlled BG_COLORS array in a terminal color library. Input is not user-supplied; no exfiltration risk. Stable false positive for this package. | ai |
Versions (showing 65 of 65)
| Version | Deps | Published |
|---|---|---|
| 2.17.0 | 0 / 5 | |
| 2.16.1 | 0 / 5 | |
| 2.16.0 | 0 / 5 | |
| 2.15.0 | 0 / 5 | |
| 2.14.0 | 0 / 5 | |
| 2.13.0 | 0 / 5 | |
| 2.12.0 | 0 / 5 | |
| 2.11.0 | 0 / 5 | |
| 2.10.0 | 0 / 5 | |
| 2.8.0 | 0 / 5 | |
| 2.7.0 | 0 / 5 | |
| 2.6.0 | 0 / 5 | |
| 2.5.0 | 0 / 5 | |
| 2.4.0 | 0 / 5 | |
| 2.3.0 | 0 / 5 | |
| 2.1.0 | 0 / 5 | |
| 2.0.0 | 0 / 5 | |
| 1.8.0 | 0 / 5 | |
| 1.6.0 | 0 / 5 | |
| 1.4.0 | 0 / 5 | |
| 1.3.0 | 0 / 5 | |
| 1.2.0 | 0 / 5 | |
| 1.1.1 | 0 / 5 | |
| 1.1.0 | 0 / 5 | |
| 1.0.1 | 0 / 5 | |
| 1.0.0 | 0 / 5 | |
| 0.63.0 | 0 / 5 | |
| 0.62.0 | 0 / 5 | |
| 0.61.0 | 0 / 5 | |
| 0.60.0 | 0 / 5 | |
| 0.59.0 | 0 / 5 | |
| 0.58.0 | 0 / 5 | |
| 0.57.0 | 0 / 5 | |
| 0.56.0 | 0 / 5 | |
| 0.55.0 | 0 / 5 | |
| 0.54.0 | 0 / 5 | |
| 0.53.0 | 0 / 6 | |
| 0.52.0 | 0 / 6 | |
| 0.51.0 | 0 / 6 | |
| 0.50.0 | 0 / 6 | |
| 0.49.0 | 0 / 6 | |
| 0.48.0 | 0 / 6 | |
| 0.47.0 | 0 / 6 | |
| 0.46.0 | 0 / 6 | |
| 0.45.0 | 0 / 6 | |
| 0.44.0 | 1 / 5 | |
| 0.43.0 | 1 / 5 | |
| 0.42.0 | 1 / 5 | |
| 0.41.0 | 1 / 5 | |
| 0.40.0 | 1 / 5 | |
| 0.39.0 | 1 / 5 | |
| 0.37.0 | 1 / 5 | |
| 0.36.0 | 1 / 5 | |
| 0.35.0 | 1 / 5 | |
| 0.34.0 | 1 / 5 | |
| 0.33.0 | 1 / 5 | |
| 0.31.0 | 1 / 5 | |
| 0.29.0 | 1 / 5 | |
| 0.28.0 | 2 / 4 | |
| 0.26.0 | 2 / 4 | |
| 0.25.0 | 2 / 4 | |
| 0.24.0 | 2 / 4 | |
| 0.21.0 | 2 / 4 | |
| 0.15.0 | 2 / 4 | |
| 0.13.0 | 1 / 4 |
v2.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.