@backstage/plugin-catalog-graph
12
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
patrikofrebenmarcuseide
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Backstage monorepo packages commonly omit description fields; not indicative of malice given clear official provenance. | ai | |
| provenance | no-provenance | AI (provenance): Backstage packages historically publish without Sigstore provenance; consistent across all versions of this package. | ai | |
| dependencies | unvetted-dep:@material-ui/icons | AI (dependencies): Well-known Material-UI icons package, standard dependency for Backstage UI plugins. | ai | |
| dependencies | unvetted-dep:@remixicon/react | AI (dependencies): Established icon library from Remix Icon, legitimate UI dependency for this plugin. | ai | |
| dependencies | unvetted-dep:@backstage/types | AI (dependencies): Official Backstage scoped package, part of the same monorepo ecosystem. Not a security risk. | ai | |
| phantom-deps | phantom-dep:@backstage/catalog-client | AI (phantom-deps): Same-org Backstage package; phantom usage is expected in monorepo builds where indirect usage is common. | ai | |
| phantom-deps | phantom-dep:p-limit | AI (phantom-deps): Common in monorepo-built packages; p-limit may be used in config/build tooling rather than direct imports. | ai | |
| dependencies | unvetted-dep:@material-ui/lab | AI (dependencies): Well-known Material-UI lab package, standard dependency for Backstage UI plugins. | ai |