← Home

@backstage/frontend-app-api

44
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

patrikofrebenmarcuseide

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/react AI (phantom-deps): Framework-scoped type dep, loaded by convention. ai
phantom-deps phantom-dep:@backstage/plugin-graphiql AI (phantom-deps): Same-org dependency, re-exported not directly imported. ai
phantom-deps phantom-dep:@backstage/types AI (phantom-deps): Same-org type-only dependency, common false positive. ai
dependencies unvetted-dep:@backstage/plugin-graphiql AI (dependencies): Official first-party Backstage plugin, same org/monorepo. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Backstage's monorepo uses 0.0.0 as intentional version convention, not throwaway signal. ai
dependencies unvetted-dep:@backstage/version-bridge AI (dependencies): @backstage/version-bridge is a legitimate same-org Backstage package; it is a stable dependency across all Backstage frontend packages. ai
phantom-deps phantom-dep:@backstage/errors AI (phantom-deps): Same-org @backstage package used transitively in a monorepo build artifact; not indicative of risk. ai
bogus-package bogus-package AI (bogus-package): Backstage monorepo packages routinely lack keywords, detailed READMEs, and descriptions on npm — this is a structural pattern, not a spam indicator. ai
npm-metadata no-description AI (npm-metadata): Backstage monorepo packages commonly omit npm descriptions; not indicative of malicious intent for this well-established package. ai
phantom-deps phantom-dep:@backstage/core-plugin-api AI (phantom-deps): Same-org Backstage dependency; indirect usage is expected in the Backstage monorepo pattern. ai
phantom-deps phantom-dep:@backstage/version-bridge AI (phantom-deps): Same-org Backstage dependency; indirect usage is expected in the Backstage monorepo pattern. ai
phantom-deps phantom-dep:@backstage/core-app-api AI (phantom-deps): Same-org Backstage dependency; indirect usage via type re-exports or config is expected in the Backstage monorepo pattern. ai
phantom-deps phantom-dep:zod AI (phantom-deps): zod is declared as a runtime dep and referenced in config schema; phantom detection may miss indirect usage patterns in Backstage monorepo packages. ai
phantom-deps phantom-dep:@backstage/frontend-defaults AI (phantom-deps): Same-org Backstage dependency; indirect usage is expected in the Backstage monorepo pattern. ai

Versions (showing 44 of 44)

Version Deps Published
0.16.6 11 / 11
0.16.5 11 / 11
0.16.4 11 / 11
0.16.3 11 / 11
0.16.2 11 / 11
0.16.1 11 / 11
0.16.0 11 / 11
0.15.0 10 / 10
0.14.1 10 / 10
0.14.0 10 / 10
0.13.3 10 / 10
0.13.2 10 / 10
0.13.1 10 / 10
0.13.0 10 / 10
0.12.0 10 / 10
0.11.4 10 / 9
0.11.3 10 / 9
0.11.2 10 / 9
0.11.1 10 / 9
0.11.0 10 / 9
0.10.5 10 / 9
0.10.4 10 / 9
0.10.3 10 / 9
0.10.2 10 / 9
0.10.1 10 / 9
0.10.0 10 / 9
0.9.0 10 / 5
0.8.0 13 / 4
0.7.4 13 / 4
0.7.3 13 / 4
0.7.2 13 / 4
0.7.1 13 / 4
0.7.0 13 / 4
0.6.4 13 / 4
0.6.3 13 / 4
0.6.2 13 / 4
0.6.1 13 / 4
0.6.0 13 / 4
0.5.0 13 / 4
0.4.0 13 / 4
0.3.0 13 / 4
0.2.0 13 / 4
0.1.0 10 / 2
0.0.0 6 / 3

v0.16.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.