Sub-Second APFS Copy-on-Write Workspaces & Zero-Mirage Git Weaving Engine
The CLI launcher can acquire and execute a native binary whose behavior is not established by the inspected JavaScript source. This is an unresolved payload execution risk, not evidence of a confirmed attack.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4When invoked, the launcher may download a platform archive from the package's GitHub releases.
bin/run.jsView on unpkg · L91The launcher executes the resolved native binary with the caller's arguments and environment; the binary payload behavior is not established by inspected JavaScript source.
bin/run.jsView on unpkg · L144Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgThe manifest defines the CLI entry point and contains no install lifecycle hook.
package.jsonView on unpkg · L1When invoked, the launcher may download a platform archive from the package's GitHub releases.
package.jsonView on unpkg · L18This report applies to @axiomantic/vine@0.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgWhen invoked, the launcher may download a platform archive from the package's GitHub releases.
bin/run.jsView on unpkg · L91The launcher executes the resolved native binary with the caller's arguments and environment; the binary payload behavior is not established by inspected JavaScript source.
bin/run.jsView on unpkg · L144The manifest defines the CLI entry point and contains no install lifecycle hook.
package.jsonView on unpkg · L1When invoked, the launcher may download a platform archive from the package's GitHub releases.
package.jsonView on unpkg · L18