@backstage/backend-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): pg-format is a legitimate Postgres helper consistent with existing pg dependency. | ai | |
| phantom-deps | phantom-dep:@backstage/types | AI (phantom-deps): Same-org monorepo dep, loaded by convention. | ai | |
| phantom-deps | phantom-dep:@google-cloud/storage | AI (phantom-deps): Framework-scoped optional integration dep. | ai | |
| phantom-deps | phantom-dep:@backstage/integration | AI (phantom-deps): Same-org monorepo dep. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Backstage releases frequently; gap reflects import history, not account takeover. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-codecommit | AI (phantom-deps): Framework-scoped optional integration dep. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/credential-providers | AI (phantom-deps): Framework-scoped optional integration dep. | ai | |
| phantom-deps | phantom-dep:@backstage/integration-aws-node | AI (phantom-deps): Same-org monorepo dep. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/abort-controller | AI (phantom-deps): Framework-scoped optional integration dep. | ai | |
| phantom-deps | phantom-dep:@types/luxon | AI (phantom-deps): Framework-scoped type definition; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@octokit/rest | AI (phantom-deps): Optional GitHub API client; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:base64-stream | AI (phantom-deps): Optional stream utility; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:concat-stream | AI (phantom-deps): Optional stream utility; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:git-url-parse | AI (phantom-deps): Optional Git utility; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): Optional database driver; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:@types/express | AI (phantom-deps): Framework-scoped type definition; loaded by convention. | ai | |
| phantom-deps | phantom-dep:path-to-regexp | AI (phantom-deps): Optional routing utility; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:@types/dockerode | AI (phantom-deps): Framework-scoped type definition; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): Framework-scoped AWS SDK client; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@types/webpack-env | AI (phantom-deps): Framework-scoped type definition; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/types | AI (phantom-deps): Framework-scoped AWS SDK type definition; loaded by convention. | ai | |
| phantom-deps | phantom-dep:tar | AI (phantom-deps): Optional archive utility; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:yauzl | AI (phantom-deps): Optional archive utility; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:mysql2 | AI (phantom-deps): Optional database driver; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:logform | AI (phantom-deps): Optional logging formatter; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:archiver | AI (phantom-deps): Optional archive utility; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:raw-body | AI (phantom-deps): Optional body parser; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:node-fetch | AI (phantom-deps): Optional HTTP client; loaded by convention in Backstage plugin architecture. | ai | |
| phantom-deps | phantom-dep:@types/cors | AI (phantom-deps): Framework-scoped type definition; loaded by convention. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 0.25.0 | 64 / 23 | |
| 0.24.1 | 64 / 23 | |
| 0.24.0 | 63 / 23 | |
| 0.23.3 | 63 / 23 | |
| 0.23.2 | 63 / 23 | |
| 0.23.1 | 63 / 23 | |
| 0.23.0 | 56 / 20 | |
| 0.22.0 | 57 / 20 |
v0.24.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.