nyc
the Istanbul command line interface
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): bcoe (Ben Coe) is the original author of nyc per package.json; this is a legitimate return to original maintainer, not a compromise. | ai | |
| dependencies | unvetted-dep:istanbul-lib-source-maps | AI (dependencies): istanbul-lib-source-maps is a core Istanbul ecosystem dependency that nyc has used across many versions; stable false positive for this package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in nyc is the intentional --require flag feature, allowing users to pre-require modules before instrumentation. This is documented behavior stable across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Isaac Schlueter is a legitimate historical contributor to nyc; his presence as a contributor does not indicate spam. False positive for this package. | ai |
Versions (showing 51 of 115)
| Version | Deps | Published |
|---|---|---|
| 18.0.0 | 27 / 9 | |
| 17.1.0 | 27 / 9 | |
| 17.0.0 | 27 / 9 | |
| 15.1.0 | 27 / 9 | |
| 15.0.1 | 26 / 9 | |
| 15.0.0 | 28 / 9 | |
| 14.1.1 | 25 / 17 | |
| 14.1.0 | 25 / 17 | |
| 14.0.0 | 24 / 15 | |
| 13.3.0 | 24 / 18 | |
| 13.2.0 | 24 / 18 | |
| 13.1.0 | 25 / 19 | |
| 13.0.1 | 25 / 19 | |
| 13.0.0 | 25 / 19 | |
| 12.0.2 | 27 / 20 | |
| 12.0.1 | 27 / 20 | |
| 12.0.0 | 27 / 20 | |
| 11.9.0 | 27 / 20 | |
| 11.8.0 | 27 / 20 | |
| 11.7.3 | 27 / 20 | |
| 11.7.2 | 27 / 20 | |
| 11.7.1 | 27 / 20 | |
| 11.7.0 | 27 / 20 | |
| 11.6.0 | 27 / 20 | |
| 11.5.0 | 27 / 21 | |
| 11.4.1 | 27 / 21 | |
| 11.4.0 | 27 / 21 | |
| 11.3.0 | 27 / 21 | |
| 11.2.1 | 27 / 20 | |
| 11.2.0 | 27 / 20 | |
| 11.1.0 | 27 / 20 | |
| 11.0.3 | 27 / 20 | |
| 11.0.2 | 27 / 20 | |
| 11.0.1 | 27 / 20 | |
| 11.0.0 | 27 / 20 | |
| 10.3.2 | 27 / 20 | |
| 10.3.1 | 27 / 20 | |
| 10.3.0 | 27 / 20 | |
| 10.2.2 | 27 / 19 | |
| 10.2.1 | 27 / 19 | |
| 10.2.0 | 27 / 19 | |
| 10.1.2 | 27 / 19 | |
| 10.1.0 | 27 / 19 | |
| 10.0.0 | 27 / 19 | |
| 9.0.1 | 26 / 19 | |
| 8.4.0 | 25 / 19 | |
| 8.3.2 | 25 / 19 | |
| 8.3.1 | 25 / 19 | |
| 8.3.0 | 25 / 19 | |
| 8.1.0 | 25 / 19 | |
| 8.0.0 | 25 / 19 |
v18.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.0.0
2 findingsThis version was published by a different npm account than previous versions on 2024-06-09. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.