Sub-Second APFS Copy-on-Write Workspaces & Zero-Mirage Git Weaving Engine
No attack was identified in the inspected launcher behavior. It selects or downloads a platform binary for the CLI and passes through the caller’s arguments.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4bin/run.js downloads a versioned asset from the project’s GitHub releases only when a compatible local or cached binary is unavailable, then launches the binary with the caller’s arguments.
bin/run.jsView on unpkg · L91bin/run.js downloads a versioned asset from the project’s GitHub releases only when a compatible local or cached binary is unavailable, then launches the binary with the caller’s arguments.
bin/run.jsView on unpkg · L144Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgpackage.json exposes bin/run.js as the CLI and declares no lifecycle scripts.
package.jsonView on unpkg · L5This report applies to @axiomantic/vine@0.2.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgbin/run.js downloads a versioned asset from the project’s GitHub releases only when a compatible local or cached binary is unavailable, then launches the binary with the caller’s arguments.
bin/run.jsView on unpkg · L91bin/run.js downloads a versioned asset from the project’s GitHub releases only when a compatible local or cached binary is unavailable, then launches the binary with the caller’s arguments.
bin/run.jsView on unpkg · L144package.json exposes bin/run.js as the CLI and declares no lifecycle scripts.
package.jsonView on unpkg · L5