← Home

@ama-sdk/create

Create a new SDK

76
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

kpanotjbourgeois-1avscaiceanu-1anicohoffmannmrednic-1asdo-1afpaul_1amatthieucrouzet-1a

Keywords

create

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is intentional CI/CD automation; backed by SLSA provenance attestation from the official org repo. ai
dependencies unvetted-dep:@angular-devkit/schematics-cli AI (dependencies): Well-known Google Angular DevKit package; stable dependency of this package across many versions. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): typescript referenced in config files for schematic tooling; stable false positive for this package. ai
phantom-deps phantom-dep:@angular/cli AI (phantom-deps): Framework-scoped dep loaded by convention in Angular schematic CLI tools; stable false positive. ai
phantom-deps phantom-dep:@ama-sdk/core AI (phantom-deps): Same-org package used by generated SDK projects; phantom detection is a false positive here. ai
phantom-deps phantom-dep:@o3r/schematics AI (phantom-deps): Schematic dependency loaded at runtime by Angular DevKit; stable false positive for this package. ai
semgrep semgrep:env-spread AI (semgrep): process.env spread into child_process spawn options is standard practice for CLI tools; comment in code explains the intent. ai
phantom-deps phantom-dep:@angular-devkit/core AI (phantom-deps): Angular DevKit peer dep loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@angular-devkit/schematics AI (phantom-deps): Angular DevKit peer dep loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@openapitools/openapi-generator-cli AI (phantom-deps): CLI tool invoked at runtime for SDK generation; phantom detection is a false positive. ai
phantom-deps phantom-dep:@schematics/angular AI (phantom-deps): Angular schematics loaded by convention via DevKit; stable false positive. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): rxjs is a transitive/peer dep used by Angular schematics; phantom detection is a false positive for this package. ai

Versions (showing 76 of 76)

Version Deps Published
14.5.0 12 / 41
14.4.4 12 / 41
14.4.3 12 / 41
14.4.2 12 / 41
14.4.1 12 / 41
14.4.0 12 / 41
14.3.4 12 / 41
14.3.3 12 / 41
14.3.2 12 / 41
14.3.1 12 / 41
14.3.0 12 / 41
14.2.6 12 / 41
14.2.3 12 / 41
14.2.1 12 / 41
14.2.0 12 / 41
14.1.13 12 / 41
14.1.12 12 / 41
14.1.11 12 / 41
14.1.10 12 / 41
14.1.9 12 / 41
14.1.8 12 / 41
14.1.7 12 / 41
14.1.6 12 / 41
14.1.4 12 / 41
14.1.1 12 / 41
14.1.0 12 / 41
14.0.13 12 / 41
14.0.12 12 / 41
14.0.10 12 / 41
14.0.8 12 / 41
14.0.5 12 / 41
14.0.4 12 / 41
14.0.3 12 / 41
14.0.1 12 / 41
14.0.0 12 / 41
13.5.13 12 / 41
13.5.12 12 / 41
13.5.11 12 / 41
13.5.10 12 / 41
13.5.8 12 / 41
13.5.7 12 / 41
13.5.4 12 / 41
13.5.3 12 / 41
13.5.2 12 / 41
13.5.1 12 / 41
13.5.0 12 / 41
13.4.5 12 / 41
13.4.4 12 / 41
13.4.2 12 / 41
13.4.1 12 / 41
13.4.0 12 / 41
13.3.3 12 / 43
13.3.2 12 / 43
13.3.1 12 / 43
13.3.0 12 / 43
13.2.9 12 / 43
13.2.8 12 / 43
13.2.7 12 / 43
13.2.6 12 / 43
13.2.5 12 / 43
13.2.4 12 / 43
13.2.3 12 / 43
13.2.2 12 / 43
13.2.1 12 / 43
13.1.11 12 / 43
13.1.10 12 / 43
13.1.9 12 / 43
13.0.19 12 / 43
13.0.18 12 / 43
13.0.17 12 / 43
13.0.16 12 / 43
13.0.15 12 / 43
12.4.25 12 / 42
12.4.24 12 / 42
12.4.23 12 / 42
12.4.22 12 / 42

v14.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.1.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.1.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.