← Home

node-fork

Look-alike nodejs 0.6.x child_process.fork() function module for nodejs 0.4.x and 0.6.x

2
Versions
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

stolsma

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:preinstall AI (install-scripts): Preinstall compiles native bindings (createpair.<version>.node) — standard pattern for this era's native addon packages. Present across all versions. ai
semgrep semgrep:child-process-import AI (semgrep): This package IS a child_process.fork() implementation; importing child_process is its core purpose, not a risk. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require loads version-specific native binding (createpair.<node_version>) — standard native addon pattern, not arbitrary module loading. ai

Versions (showing 2 of 2)

Version Deps Published
0.4.2 0 / 1
0.3.0 0 / 1

v0.4.2

3 findings
HIGH Package has 'preinstall' script install-scripts

Script: bash ./install

HIGH Unclaimed maintainer email domain: sander at tolsma.net email-domain

Maintainer email 'sander at tolsma.net' uses domain 'sander at tolsma.net' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

2 findings
HIGH Unclaimed maintainer email domain: sander at tolsma.net email-domain

Maintainer email 'sander at tolsma.net' uses domain 'sander at tolsma.net' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.