Sub-Second APFS Copy-on-Write Workspaces & Zero-Mirage Git Weaving Engine
No attack was identified in the inspected launcher source. It selects a native CLI binary, downloading a versioned release from the package’s repository if needed, then invokes it for the user’s command.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4bin/run.js downloads a versioned native binary from the package’s GitHub release and runs it with the caller’s arguments and environment.
bin/run.jsView on unpkg · L94bin/run.js downloads a versioned native binary from the package’s GitHub release and runs it with the caller’s arguments and environment.
bin/run.jsView on unpkg · L140Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgpackage.json exposes bin/run.js as the package CLI entry point.
package.jsonView on unpkg · L5This report applies to @axiomantic/vine@0.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgbin/run.js downloads a versioned native binary from the package’s GitHub release and runs it with the caller’s arguments and environment.
bin/run.jsView on unpkg · L94bin/run.js downloads a versioned native binary from the package’s GitHub release and runs it with the caller’s arguments and environment.
bin/run.jsView on unpkg · L140package.json exposes bin/run.js as the package CLI entry point.
package.jsonView on unpkg · L5