machinepack-process
Work with child procs and the running process.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): machinepack-process explicitly wraps child_process as its core functionality (execute-command, spawn-child-process machines). This import is intentional and documented. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): rachaelshaw is a long-standing Sails.js/Treeline ecosystem contributor (750 approved packages, 3457 days history) — a legitimate team transition, not a takeover. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 4.0.1 | 3 / 4 | |
| 4.0.0 | 4 / 4 | |
| 2.0.2 | 7 / 4 | |
| 2.0.1 | 3 / 4 | |
| 2.0.0 | 3 / 4 | |
| 1.4.0 | 4 / 1 | |
| 1.3.0 | 3 / 1 | |
| 1.2.3 | 3 / 1 | |
| 1.2.1 | 3 / 1 | |
| 1.2.0 | 3 / 1 | |
| 1.1.0 | 3 / 1 | |
| 1.0.2 | 2 / 1 | |
| 1.0.1 | 2 / 1 | |
| 1.0.0 | 2 / 1 |
v4.0.1
2 findingsThis version was published by a different npm account than previous versions on 2019-04-22. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.