← Home

@availity/workflow

Upgradable workflow for Availity boilerplate projects

8
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

dnolerjseldencbaker1twarnergregmartdotinhnicbakerchrishavekostjordan-a-youngavaility-cicd-botlauroxx

Keywords

boilerplateworkflowavailityreact

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
email-domain unclaimed-email:heatherdev.net AI (email-domain): Long-standing org package; publish is CI-driven, not tied to personal email control. ai
publish-pattern new-deps-added AI (publish-pattern): Added deps are standard testing-library packages, part of Vitest migration. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped; loaded by convention in babel/webpack toolchain. ai
phantom-deps phantom-dep:type-is AI (phantom-deps): MIME type utility; used transitively in dev server config. ai
semgrep semgrep:child-process-import AI (semgrep): Lint script uses spawnSync to invoke linter; standard for a workflow/build tool. ai
phantom-deps phantom-dep:regenerator-runtime AI (phantom-deps): Known implicit Babel runtime dependency. ai
phantom-deps phantom-dep:figures AI (phantom-deps): CLI display utility; likely used transitively by logger. ai
phantom-deps phantom-dep:pretty-ms AI (phantom-deps): Timing display utility; used transitively in build output. ai
phantom-deps phantom-dep:file-loader AI (phantom-deps): Webpack loader referenced in config; standard workflow tool pattern. ai
phantom-deps phantom-dep:postcss-loader AI (phantom-deps): Webpack loader referenced in config; standard workflow tool pattern. ai
phantom-deps phantom-dep:imports-loader AI (phantom-deps): Webpack loader referenced in config; standard workflow tool pattern. ai
phantom-deps phantom-dep:esbuild-loader AI (phantom-deps): Webpack loader referenced in config; standard workflow tool pattern. ai
phantom-deps phantom-dep:react-refresh AI (phantom-deps): Used via @pmmmwh/react-refresh-webpack-plugin config; not directly imported. ai
phantom-deps phantom-dep:jsdom AI (phantom-deps): Test environment dependency referenced in jest config; not directly imported. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in jest.config.js for optional user init file; expected pattern for a configurable workflow tool. ai
phantom-deps phantom-dep:webpack-sources AI (phantom-deps): Webpack internal referenced in plugin config; standard workflow tool pattern. ai
phantom-deps phantom-dep:jest-environment-jsdom AI (phantom-deps): Jest environment referenced in config; not directly imported. ai
phantom-deps phantom-dep:eslint-config-availity AI (phantom-deps): ESLint config package loaded by convention, not direct import. ai
phantom-deps phantom-dep:babel-plugin-root-import AI (phantom-deps): Babel plugin referenced in babel config; not directly imported. ai
phantom-deps phantom-dep:babel-plugin-jsx-remove-data-test-id AI (phantom-deps): Babel plugin referenced in babel config; not directly imported. ai
phantom-deps phantom-dep:process AI (phantom-deps): Node polyfill referenced in webpack config; standard workflow tool pattern. ai
semgrep semgrep:env-bulk-read AI (semgrep): settings/index.js filters process.env keys against a known config allowlist; standard config-library pattern. ai
phantom-deps phantom-dep:sass AI (phantom-deps): Build tool that exposes sass as a peer/optional loader; not directly imported by convention. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): PostCSS is a peer dependency used via postcss-loader config; standard build-tool pattern. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Webpack loader referenced in config, not imported directly; expected for a workflow tool. ai
phantom-deps phantom-dep:babel-loader AI (phantom-deps): Webpack loader referenced in config; standard workflow tool pattern. ai
phantom-deps phantom-dep:sass-loader AI (phantom-deps): Webpack loader referenced in config; standard workflow tool pattern. ai
phantom-deps phantom-dep:style-loader AI (phantom-deps): Webpack loader referenced in config; standard workflow tool pattern. ai

Versions (showing 8 of 8)

Version Deps Published
14.0.0 49 / 0
13.0.3 71 / 3
13.0.2 71 / 3
13.0.0 71 / 3
12.2.5 79 / 3
12.2.4 79 / 3
12.2.3 78 / 3
12.2.1 78 / 3

v14.0.0

2 findings
HIGH Unclaimed maintainer email domain: heatherdev.net email-domain

Maintainer email '[email protected]' uses domain 'heatherdev.net' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.