← Home

pug

A clean, whitespace-sensitive template language for writing HTML

1
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

forbeslindesaypug-bot

Keywords

htmljadepugtemplate

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:pg AI (typosquat): pug is a well-established template engine (pugjs.org); the name predates and is unrelated to the pg PostgreSQL client. Not a typosquat. ai
typosquat typosquat.levenshtein:yup AI (typosquat): pug is a well-established template engine; 2-edit distance from yup is coincidental. Not a typosquat. ai
semgrep semgrep:new-function-constructor AI (semgrep): new Function() is the core compilation mechanism of the pug template engine — it compiles templates to JS functions. This is expected, documented behavior for this package. ai

Versions (showing 1 of 1)

Version Deps Published
3.0.4 8 / 10