@backstage/plugin-app
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@backstage/filter-predicates | AI (phantom-deps): Same-org scoped package, heuristic false positive. | ai | |
| dependencies | unvetted-dep:zen-observable | AI (dependencies): Standard observable lib used widely in Backstage ecosystem, no malicious behavior. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Backstage monorepo packages omit description; benign. | ai | |
| phantom-deps | phantom-dep:@material-ui/lab | AI (phantom-deps): Referenced via config/convention in Backstage plugin. | ai | |
| dependencies | unvetted-dep:@material-ui/lab | AI (dependencies): Standard MUI v4 dep used across Backstage frontend plugins. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Framework type dep loaded by convention. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Official Backstage monorepo plugin; sparse README metadata is not spam for this established namespace. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.4.5 | 22 / 13 | |
| 0.1.8 | 11 / 11 | |
| 0.1.7 | 11 / 11 | |
| 0.1.6 | 10 / 11 | |
| 0.1.5 | 10 / 11 | |
| 0.1.4 | 10 / 11 | |
| 0.1.3 | 10 / 11 | |
| 0.1.2 | 10 / 11 | |
| 0.1.1 | 10 / 11 | |
| 0.1.0 | 10 / 8 |
v0.4.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.8
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.7
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.6
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Package impersonates @backstage/plugin-app but is published by an unknown account with no history; bogus indicators are consistent with malicious namespace squatting.) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.