← Home

tiny-glob

Tiny and extremely fast globbing

16
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

terkelg

Keywords

globglobbingpatternswildcardpattern-matchingexpansion

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:globrex AI (dependencies): globrex is a known companion package by the same author (terkelg); it is a stable, well-established dependency of tiny-glob across all versions. ai
dependencies unvetted-dep:globalyzer AI (dependencies): globalyzer is a known companion package by the same author (terkelg); it is a stable, well-established dependency of tiny-glob across all versions. ai
bogus-package bogus-package AI (bogus-package): v0.0.1 is a legitimate historical placeholder release from a trusted publisher (terkelg) over 8 years ago; sparse metadata is expected for early stub releases. ai
npm-metadata no-description AI (npm-metadata): No description is expected for this initial v0.0.1 stub release from a verified legitimate publisher; not indicative of malicious intent. ai
provenance no-provenance AI (provenance): tiny-glob is a long-established package predating Sigstore provenance; absence of attestation is expected and not a security concern here. ai

Versions (showing 16 of 16)

Version Deps Published
0.2.9 2 / 2
0.2.8 2 / 2
0.2.7 2 / 2
0.2.6 2 / 2
0.2.5 2 / 2
0.2.4 2 / 2
0.2.3 2 / 2
0.2.2 2 / 2
0.2.1 2 / 2
0.2.0 2 / 2
0.1.3 2 / 2
0.1.2 2 / 2
0.1.1 2 / 2
0.1.0 2 / 2
0.0.2 2 / 2
0.0.1 0 / 0