← Home

parse-commit-message

Extensible parser for git commit messages following Conventional Commits Specification

39
Versions
MPL-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

tunnckocore

Keywords

commit message parsercommit messagescommit-messagecommit-parsercommitscommits-parserconventionalconventional-commitsconventionalcommitsdeveloper-experiencedevelopmentdxhelaparse commit messageparse-commitparse-commit-messageparse-commitsparsertunnckocore-osstunnckocorehq

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): v5 is a major rewrite to TypeScript with dual ESM/CJS output via tsup; new files are legitimate source and dist artifacts, not injected code. ai
source-diff source-size-tripled AI (source-diff): Size increase from 244B to 101KB reflects migration to TypeScript with compiled dist output; consistent with a major version rewrite, not payload injection. ai
npm-metadata no-description AI (npm-metadata): Package clearly has a description in package.json; this is a false positive for this package. ai
bogus-package bogus-package AI (bogus-package): Package has description, keywords, repository URL, and runtime deps — bogus-package signals are false positives for this established package. ai

Versions (showing 39 of 39)

Version Deps Published
5.0.4 2 / 4
5.0.3 2 / 4
5.0.2 0 / 0
5.0.1 2 / 4
5.0.0 0 / 0
4.1.3 0 / 4
4.1.2 0 / 4
4.1.1 0 / 4
4.1.0 0 / 4
4.0.2 0 / 4
4.0.1 0 / 4
4.0.0 0 / 4
3.3.0 0 / 4
3.2.3 4 / 2
3.2.2 4 / 2
3.2.1 4 / 2
3.2.0 4 / 2
3.1.0 4 / 2
3.0.1 4 / 2
3.0.0 4 / 2
2.1.4 1 / 18
2.1.3 1 / 18
2.1.2 1 / 18
2.1.1 1 / 18
2.1.0 1 / 18
2.0.6 1 / 12
2.0.4 1 / 12
2.0.3 2 / 7
2.0.2 2 / 7
2.0.1 2 / 7
2.0.0 2 / 7
1.1.2 2 / 5
1.1.1 2 / 5
1.1.0 2 / 5
1.0.0 2 / 5
0.2.0 0 / 3
0.1.2 0 / 3
0.1.1 0 / 3
0.1.0 0 / 3

v5.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tunnckocore.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: tunnckocore.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.