← Home

@backstage/plugin-catalog-react

6
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

patrikofrebenmarcuseide

Keywords

backstage

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@remixicon/react AI (dependencies): Legitimate icon library newly added in this version; no security concern. ai
dependencies unvetted-dep:@backstage/version-bridge AI (dependencies): Same org scope (@backstage); a core Backstage utility package used throughout the monorepo. ai
dependencies unvetted-dep:@material-ui/icons AI (dependencies): @material-ui/icons is a well-known MUI icon package; standard dependency for Backstage UI plugins. ai
dependencies unvetted-dep:material-ui-popup-state AI (dependencies): material-ui-popup-state is a widely-used MUI utility; no security concerns for this package context. ai
dependencies unvetted-dep:zen-observable AI (dependencies): zen-observable is a well-known observable library; its use in Backstage catalog-react is legitimate and stable across versions. ai
dependencies unvetted-dep:@backstage/types AI (dependencies): Same org scope (@backstage); a core Backstage utility package used throughout the monorepo. ai
dependencies unvetted-dep:@material-ui/lab AI (dependencies): @material-ui/lab is a well-known MUI component package; its use in Backstage UI plugins is standard and long-standing. ai
dependencies unvetted-dep:@react-hookz/web AI (dependencies): @react-hookz/web is a reputable React hooks library; no security concerns for this package context. ai
provenance no-provenance AI (provenance): Official Backstage monorepo package; lack of Sigstore provenance is common and not a disqualifier for this well-established package. ai
phantom-deps phantom-dep:@backstage/plugin-catalog-common AI (phantom-deps): Package is listed in both dependencies and devDependencies in the Backstage monorepo — a known packaging pattern, not a security concern. ai

Versions (showing 6 of 6)

Version Deps Published
2.1.4 28 / 16
2.1.3 28 / 16
2.1.2 28 / 16
2.1.1 26 / 17
1.21.5 25 / 16
1.21.3 25 / 16

v2.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.