← Home

@backstage/backend-common

1
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

patrikofrebenmarcuseide

Keywords

backstage

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:pg AI (phantom-deps): Optional database driver; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:tar AI (phantom-deps): Optional archive utility; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:yauzl AI (phantom-deps): Optional archive utility; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:mysql2 AI (phantom-deps): Optional database driver; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:logform AI (phantom-deps): Optional logging formatter; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:archiver AI (phantom-deps): Optional archive utility; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:raw-body AI (phantom-deps): Optional body parser; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Optional HTTP client; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:@types/cors AI (phantom-deps): Framework-scoped type definition; loaded by convention. ai
phantom-deps phantom-dep:@types/luxon AI (phantom-deps): Framework-scoped type definition; loaded by convention. ai
phantom-deps phantom-dep:@octokit/rest AI (phantom-deps): Optional GitHub API client; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:base64-stream AI (phantom-deps): Optional stream utility; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:concat-stream AI (phantom-deps): Optional stream utility; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:git-url-parse AI (phantom-deps): Optional Git utility; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:@aws-sdk/types AI (phantom-deps): Framework-scoped AWS SDK type definition; loaded by convention. ai
phantom-deps phantom-dep:@types/express AI (phantom-deps): Framework-scoped type definition; loaded by convention. ai
phantom-deps phantom-dep:path-to-regexp AI (phantom-deps): Optional routing utility; loaded by convention in Backstage plugin architecture. ai
phantom-deps phantom-dep:@types/dockerode AI (phantom-deps): Framework-scoped type definition; loaded by convention. ai
phantom-deps phantom-dep:@aws-sdk/client-s3 AI (phantom-deps): Framework-scoped AWS SDK client; loaded by convention. ai
phantom-deps phantom-dep:@types/webpack-env AI (phantom-deps): Framework-scoped type definition; loaded by convention. ai

Versions (showing 1 of 1)

Version Deps Published
0.25.0 64 / 23

v0.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.