← Home

@automattic/jetpack-shared-extension-utils

Utility functions used by the block editor extensions

51
Versions
GPL-2.0-or-later
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

macbreyuliyanmjangdamatticbota8cbloweryehg_sgomestyxlasaroshaganejclovrencicsirbrilligchriszaraterobersongomesjohngodleyjehervedaledupreez-a8ct2dw4tluismulinariandrea-sdlelazzabifmfernandessirrealwwachihsuanmanzoorwanijkmsurdi-a8cnewspack-npmdsmartgkthai15bgrgicakrobertsreberski_a8cartpigmjuhaszborkwebkat3samsinbrunobastodhenridevmrmurphywpvip-botetobiesenalshakeroarthur791004diliritymehmoodaknatalia.vidalivan.ottingeranandnalyaarcangelinisretrofoxiamchughmayanksimisonfredrikekelundchriskmndsoandregalgalatanovidiukangzj_mirka_aduthebuccelli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@wordpress/api-fetch AI (phantom-deps): WordPress peer dependency pattern; stable false positive for this block editor utility package. ai
phantom-deps phantom-dep:@wordpress/block-editor AI (phantom-deps): WordPress peer dependency pattern; stable false positive for this block editor utility package. ai
phantom-deps phantom-dep:@wordpress/primitives AI (phantom-deps): WordPress peer dependency pattern; stable false positive for this block editor utility package. ai
provenance publisher-changed AI (provenance): Automattic migrated Jetpack publishing to GitHub Actions CI; stable pattern across this package family. ai
phantom-deps phantom-dep:@types/jest AI (phantom-deps): Test-framework type package; loaded by convention, not direct import. Stable FP for this package. ai
bogus-package bogus-package AI (bogus-package): Legitimate Automattic monorepo package; README link dump and missing keywords are typical for internal utility packages. ai
phantom-deps phantom-dep:@automattic/jetpack-base-styles AI (phantom-deps): Same-org CSS/styles package; likely consumed via build tooling, not direct JS import. Stable FP. ai

Versions (showing 51 of 89)

View all versions
Version Deps Published
2.0.11 24 / 13
2.0.10 24 / 13
2.0.9 24 / 13
2.0.8 24 / 13
2.0.6 23 / 13
2.0.5 23 / 12
2.0.4 23 / 14
2.0.3 23 / 14
2.0.2 23 / 14
2.0.1 23 / 14
2.0.0 22 / 14
1.5.22 22 / 14
1.5.21 22 / 14
1.5.20 22 / 14
1.5.19 22 / 14
1.5.18 22 / 14
1.5.17 22 / 14
1.5.16 22 / 14
1.5.15 22 / 14
1.5.14 22 / 14
1.5.13 22 / 14
1.5.12 21 / 14
1.5.11 21 / 14
1.5.10 21 / 14
1.5.9 21 / 14
1.5.8 21 / 14
1.5.7 21 / 14
1.5.6 21 / 14
1.5.5 21 / 14
1.5.4 21 / 14
1.5.3 21 / 14
1.5.2 21 / 14
1.5.1 21 / 14
1.5.0 21 / 14
1.4.13 21 / 14
1.4.12 21 / 14
1.4.11 21 / 14
1.4.10 21 / 14
1.4.9 21 / 14
1.4.8 21 / 14
1.4.7 21 / 14
1.4.6 21 / 14
1.4.5 21 / 14
1.4.4 21 / 15
1.4.3 21 / 15
1.4.2 21 / 15
1.4.1 21 / 15
1.4.0 21 / 15
1.3.28 21 / 15
1.3.27 21 / 15
1.3.26 21 / 15

v2.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.