@backstage-community/plugin-todo-backend
A Backstage backend plugin that lets you browse TODO comments in your source code
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:leasot | AI (dependencies): leasot is a legitimate TODO-comment parser; its use is the core function of this todo-backend plugin. | ai | |
| phantom-deps | phantom-dep:yn | AI (phantom-deps): yn is a runtime dep used indirectly; phantom-dep heuristic fires but it's legitimately declared. | ai | |
| phantom-deps | phantom-dep:@types/express | AI (phantom-deps): Framework-scoped type package; phantom-dep false positive for backend plugins using express. | ai | |
| phantom-deps | phantom-dep:@backstage/catalog-client | AI (phantom-deps): Backstage backend plugin convention; catalog-client is used via DI, not direct import. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 0.23.0 | 13 / 5 | |
| 0.22.0 | 13 / 5 | |
| 0.21.1 | 13 / 5 | |
| 0.21.0 | 13 / 5 | |
| 0.20.0 | 13 / 5 | |
| 0.19.0 | 13 / 5 | |
| 0.18.1 | 13 / 5 | |
| 0.18.0 | 13 / 5 | |
| 0.17.0 | 13 / 5 | |
| 0.16.0 | 13 / 5 | |
| 0.15.0 | 13 / 5 | |
| 0.14.0 | 13 / 5 | |
| 0.13.0 | 13 / 5 | |
| 0.12.0 | 13 / 5 | |
| 0.11.0 | 13 / 5 | |
| 0.10.0 | 13 / 5 | |
| 0.9.0 | 13 / 5 | |
| 0.8.0 | 13 / 5 | |
| 0.7.0 | 13 / 5 | |
| 0.6.0 | 13 / 5 | |
| 0.5.0 | 13 / 5 | |
| 0.4.0 | 13 / 5 | |
| 0.3.22 | 13 / 5 | |
| 0.3.21 | 13 / 5 | |
| 0.3.20 | 13 / 5 | |
| 0.3.19 | 13 / 4 | |
| 0.3.18 | 13 / 4 | |
| 0.3.17 | 13 / 4 | |
| 0.3.16 | 14 / 4 | |
| 0.3.15 | 14 / 4 |
v0.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.