@backstage/plugin-techdocs-addons-test-utils
9
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
patrikofrebenmarcuseide
Keywords
backstagetechdocs
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:testing-library__dom | AI (dependencies): The testing-library__dom dep is a known Backstage monorepo artifact (flattened scoped package name). Consistent across versions; no malicious indicators. | ai | |
| dependencies | unvetted-dep:shadow-dom-testing-library | AI (dependencies): shadow-dom-testing-library is a legitimate testing utility appropriate for a TechDocs addons test utils package; stable dependency for this package's purpose. | ai | |
| bogus-package | bogus-package | AI (bogus-package): This is a test utility package in the Backstage monorepo; sparse README and description are expected for internal tooling packages, not spam indicators. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Backstage monorepo test utility packages commonly lack verbose descriptions; not a malicious signal for this well-established scoped package. | ai | |
| phantom-deps | phantom-dep:@backstage/plugin-catalog | AI (phantom-deps): Phantom dep in a monorepo package is expected; @backstage/plugin-catalog is a legitimate same-org dependency used transitively or in type declarations. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 2.0.7 | 10 / 7 | |
| 2.0.6 | 10 / 7 | |
| 2.0.5 | 10 / 7 | |
| 2.0.4 | 10 / 7 | |
| 2.0.3 | 10 / 7 | |
| 2.0.2 | 10 / 7 | |
| 2.0.1 | 10 / 7 | |
| 2.0.0 | 10 / 7 | |
| 1.1.2 | 10 / 7 |
v2.0.7
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.