← Home

microbundle-crl

1
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

fisch0920

Keywords

bundlerollupmicro library

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:tslib AI (phantom-deps): Bundler ships tslib as a runtime peer; loaded by convention, not direct import. ai
phantom-deps phantom-dep:filesize AI (phantom-deps): Referenced in config/output formatting; stable false positive for this bundler. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Framework-scoped Babel preset loaded by convention in bundler context. ai
phantom-deps phantom-dep:rollup-plugin-es3 AI (phantom-deps): Rollup plugin loaded by config reference, not direct import; expected pattern. ai
phantom-deps phantom-dep:@babel/preset-flow AI (phantom-deps): Framework-scoped Babel preset; loaded by convention. ai
phantom-deps phantom-dep:babel-plugin-macros AI (phantom-deps): Babel plugin loaded via config, not direct import; expected for bundler. ai
phantom-deps phantom-dep:@babel/plugin-syntax-jsx AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention. ai
phantom-deps phantom-dep:module-details-from-path AI (phantom-deps): Referenced in config files; stable false positive for this bundler. ai
phantom-deps phantom-dep:rollup-plugin-bundle-size AI (phantom-deps): Rollup plugin loaded by config reference; expected pattern. ai
phantom-deps phantom-dep:@babel/plugin-proposal-decorators AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-transform-react-jsx AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-proposal-class-properties AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-proposal-optional-chaining AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-transform-flow-strip-types AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention. ai
phantom-deps phantom-dep:babel-plugin-transform-async-to-promises AI (phantom-deps): Babel plugin loaded via config reference; expected for bundler. ai

Versions (showing 1 of 1)

Version Deps Published
0.13.11 41 / 23

v0.13.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.