← Home

@adyen/adyen-salesforce-pwa

This NPM package enables you to go live fast with payments with Adyen as a payment service provider when building your Salesforce PWA Retail application.

11
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

adyencomborysfromadyenvergilfromadyencamilocvalexandrefromadyennostalgic-octopus

Keywords

adyensalesforcepwacheckoutpaymentpaymentscomponents

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/scripts/update-notifier.js AI (source-diff): Minified bundle of legit update-notifier dep, not custom obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): update-notifier is a well-known, widely-used package added for the postinstall check. ai
install-scripts install-script:postinstall AI (install-scripts): Local script wrapping update-notifier; standard version-check pattern, no fetched code. ai
dependencies unvetted-dep:@adyen/api-library AI (dependencies): First-party Adyen library; same org scope as this package, stable dependency across versions. ai
phantom-deps phantom-dep:framer-motion AI (phantom-deps): UI dep referenced in config; stable false positive for this PWA plugin. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): Chakra-UI peer dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): Chakra-UI peer dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@adyen/api-library AI (phantom-deps): Same org scope; likely used indirectly via re-exports or config; stable false positive. ai
phantom-deps phantom-dep:commerce-sdk-isomorphic AI (phantom-deps): Salesforce PWA SDK dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@salesforce/pwa-kit-runtime AI (phantom-deps): PWA runtime dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): PWA plugin; react-dom is a peer/transitive dep referenced in config, not directly imported. ai
phantom-deps phantom-dep:express-validator AI (phantom-deps): Validation in CLI scripts; stable pattern for this package. ai
phantom-deps phantom-dep:update-notifier AI (phantom-deps): CLI update-check script; stable pattern for this package. ai
phantom-deps phantom-dep:minimist AI (phantom-deps): CLI argument parsing; stable pattern for this package. ai
phantom-deps phantom-dep:body-parser AI (phantom-deps): Express middleware in config; stable pattern for this package. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Config-file reference in CLI scripts; stable pattern for this package. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): HTTP utility in CLI scripts; stable pattern for this package. ai

Versions (showing 11 of 11)

Version Deps Published
4.4.0 6 / 31
4.3.0 6 / 31
4.2.2 6 / 31
4.2.1 6 / 31
4.2.0 7 / 27
4.1.1 6 / 27
4.1.0 6 / 27
4.0.0 6 / 27
3.0.4 15 / 23
3.0.3 15 / 23
3.0.2 15 / 23

v4.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.1

3 findings
HIGH New obfuscated file: dist/scripts/update-notifier.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: alexandrefromadyen → GitHub Actions (on 2026-03-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (alexandrefromadyen) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.2.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node ./lib/scripts/update-notifier.js

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.