@backstage/plugin-auth-backend
A Backstage backend plugin that handles authentication
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:connect-session-knex | AI (dependencies): connect-session-knex is a legitimate, well-known session store for Knex/Express and has been a stable dependency of this plugin across many versions. No malicious signals. | ai | |
| provenance | no-provenance | AI (provenance): Official Backstage monorepo package; lack of Sigstore provenance is consistent across all @backstage/* packages and is not a risk indicator for this well-established project. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.29.2 | 23 / 11 | |
| 0.29.1 | 23 / 11 | |
| 0.29.0 | 23 / 11 | |
| 0.28.0 | 24 / 11 | |
| 0.27.3 | 24 / 11 | |
| 0.27.2 | 24 / 11 | |
| 0.27.1 | 24 / 11 |
v0.29.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.