rollup
Next-generation ES module bundler
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Versions (showing 51 of 616)
| Version | Deps | Published |
|---|---|---|
| 4.60.4 | 1 / 91 | |
| 4.60.3 | 1 / 91 | |
| 4.60.2 | 1 / 87 | |
| 4.60.1 | 1 / 88 | |
| 4.60.0 | 1 / 88 | |
| 4.59.1 | 1 / 87 | |
| 4.59.0 | 1 / 87 | |
| 2.80.0 | 0 / 59 | |
| 2.79.1 | 1 / 59 | |
| 2.79.0 | 1 / 59 | |
| 2.78.1 | 1 / 59 | |
| 2.78.0 | 1 / 59 | |
| 2.77.3 | 1 / 59 | |
| 2.77.2 | 1 / 59 | |
| 2.77.1 | 1 / 59 | |
| 2.77.0 | 1 / 59 | |
| 2.76.0 | 1 / 59 | |
| 2.75.7 | 1 / 59 | |
| 2.75.6 | 1 / 59 | |
| 2.75.5 | 1 / 59 | |
| 2.75.4 | 1 / 59 | |
| 2.75.3 | 1 / 59 | |
| 2.75.2 | 1 / 59 | |
| 2.75.1 | 1 / 59 | |
| 2.75.0 | 1 / 59 | |
| 2.74.1 | 1 / 59 | |
| 2.74.0 | 1 / 59 | |
| 2.73.0 | 1 / 59 | |
| 2.72.1 | 1 / 59 | |
| 2.72.0 | 1 / 59 | |
| 2.71.1 | 1 / 59 | |
| 2.71.0 | 1 / 59 | |
| 2.70.2 | 1 / 59 | |
| 2.70.1 | 1 / 59 | |
| 2.70.0 | 1 / 59 | |
| 2.69.2 | 1 / 60 | |
| 2.69.1 | 1 / 60 | |
| 2.69.0 | 1 / 60 | |
| 2.68.0 | 1 / 60 | |
| 2.67.3 | 1 / 60 | |
| 2.67.2 | 1 / 60 | |
| 2.67.1 | 1 / 59 | |
| 2.67.0 | 1 / 59 | |
| 2.66.1 | 1 / 59 | |
| 2.66.0 | 1 / 59 | |
| 2.65.0 | 1 / 59 | |
| 2.64.0 | 1 / 61 | |
| 2.63.0 | 1 / 61 | |
| 2.62.0 | 1 / 61 | |
| 2.61.1 | 1 / 61 | |
| 2.61.0 | 1 / 61 |
v4.60.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.60.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.60.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.60.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.59.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.59.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.80.0
5 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account than previous versions on 2026-02-22. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.