← Home

nyc

the Istanbul command line interface

15
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

isaacsbcoecoreyfarrell

Keywords

coveragereportersubprocesstesting

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): bcoe (Ben Coe) is the original author of nyc per package.json; this is a legitimate return to original maintainer, not a compromise. ai
dependencies unvetted-dep:istanbul-lib-source-maps AI (dependencies): istanbul-lib-source-maps is a core Istanbul ecosystem dependency that nyc has used across many versions; stable false positive for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in nyc is the intentional --require flag feature, allowing users to pre-require modules before instrumentation. This is documented behavior stable across all versions. ai
bogus-package bogus-package AI (bogus-package): Isaac Schlueter is a legitimate historical contributor to nyc; his presence as a contributor does not indicate spam. False positive for this package. ai

Versions (showing 15 of 115)

Version Deps Published
2.0.0 10 / 4
1.4.1 10 / 4
1.4.0 10 / 4
1.3.0 8 / 4
1.2.0 7 / 4
1.1.9 7 / 4
1.1.8 6 / 4
1.1.7 7 / 4
1.1.6 7 / 4
1.1.5 6 / 4
1.1.4 6 / 4
1.1.3 7 / 4
1.1.2 7 / 4
1.1.1 6 / 3
1.1.0 6 / 3