@backstage-community/plugin-mend-backend
6
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
patriko
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:yn | AI (phantom-deps): Config-driven dependency; stable pattern for Backstage plugins. | ai | |
| phantom-deps | phantom-dep:winston | AI (phantom-deps): Logging framework loaded by convention in Backstage backend plugins. | ai | |
| phantom-deps | phantom-dep:node-fetch | AI (phantom-deps): Transitive or config-driven dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:@types/express | AI (phantom-deps): Framework-scoped types loaded by convention in Express-based Backstage plugins. | ai | |
| phantom-deps | phantom-dep:@backstage/config | AI (phantom-deps): Backstage config loaded by plugin infrastructure, not direct import. | ai | |
| phantom-deps | phantom-dep:@backstage/catalog-model | AI (phantom-deps): Backstage catalog-model loaded by plugin infrastructure, not direct import. | ai |