@backstage/repo-tools
CLI for Backstage repo tooling
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): @prettier/sync is an official Prettier package; addition is benign and consistent with this CLI's formatting use case. | ai | |
| dependencies | unvetted-dep:yaml-diff-patch | AI (dependencies): yaml-diff-patch is a small YAML patching utility; appropriate for a repo tooling package. | ai | |
| dependencies | unvetted-dep:knip | AI (dependencies): knip is a well-known dead-code/unused-exports finder; legitimate dev tooling dependency for a repo-tools CLI. | ai | |
| dependencies | unvetted-dep:@microsoft/api-documenter | AI (dependencies): Part of Microsoft's API toolchain, consistent with the already-approved @microsoft/api-extractor dependency in this package. | ai | |
| dependencies | unvetted-dep:@useoptic/openapi-utilities | AI (dependencies): Optic's OpenAPI utilities; legitimate OpenAPI tooling used by this repo-tools CLI. | ai | |
| dependencies | unvetted-dep:@apisyouwonthate/style-guide | AI (dependencies): APIs You Won't Hate style guide for Spectral; legitimate OpenAPI linting ruleset. | ai | |
| dependencies | unvetted-dep:@stoplight/spectral-rulesets | AI (dependencies): Stoplight Spectral rulesets; standard OpenAPI linting component used alongside other @stoplight packages. | ai | |
| dependencies | unvetted-dep:@stoplight/spectral-formatters | AI (dependencies): Stoplight Spectral formatters; standard OpenAPI linting component, consistent with other @stoplight deps. | ai | |
| dependencies | unvetted-dep:@openapitools/openapi-generator-cli | AI (dependencies): OpenAPI Generator CLI; well-known code generation tool appropriate for a repo-tools CLI. | ai | |
| phantom-deps | phantom-dep:@electric-sql/pglite | AI (phantom-deps): pglite is used as a runtime dependency for database tooling features; referenced in config files is expected for this package. | ai | |
| phantom-deps | phantom-dep:@backstage/catalog-model | AI (phantom-deps): Same-org Backstage dependency; phantom detection is a false positive for this monorepo CLI tool. | ai | |
| phantom-deps | phantom-dep:@stoplight/spectral-runtime | AI (phantom-deps): Spectral runtime is a transitive/config-level dependency for OpenAPI linting; phantom detection is a false positive here. | ai | |
| phantom-deps | phantom-dep:@openapitools/openapi-generator-cli | AI (phantom-deps): openapi-generator-cli is invoked as a CLI tool via config, not directly imported; phantom detection is a false positive for this tooling package. | ai | |
| provenance | no-provenance | AI (provenance): Backstage packages historically do not publish with Sigstore provenance; this is consistent across the ecosystem and not a risk signal. | ai | |
| phantom-deps | phantom-dep:is-glob | AI (phantom-deps): is-glob is a utility dependency used in config/helper contexts; phantom detection is a false positive for this CLI tooling package. | ai | |
| phantom-deps | phantom-dep:knip | AI (phantom-deps): knip is declared as a dependency and used as a CLI tool invoked via config; not directly imported in source is expected for this tooling package. | ai |
Versions (showing 35 of 35)
| Version | Deps | Published |
|---|---|---|
| 0.18.0 | 42 / 7 | |
| 0.17.3 | 44 / 7 | |
| 0.17.2 | 44 / 7 | |
| 0.17.1 | 44 / 7 | |
| 0.17.0 | 44 / 7 | |
| 0.16.5 | 44 / 7 | |
| 0.16.4 | 44 / 7 | |
| 0.16.3 | 43 / 7 | |
| 0.16.2 | 43 / 7 | |
| 0.16.1 | 43 / 7 | |
| 0.16.0 | 43 / 7 | |
| 0.15.4 | 43 / 7 | |
| 0.15.3 | 43 / 7 | |
| 0.15.2 | 43 / 7 | |
| 0.15.1 | 43 / 7 | |
| 0.15.0 | 43 / 7 | |
| 0.14.0 | 43 / 7 | |
| 0.13.4 | 41 / 7 | |
| 0.13.3 | 41 / 7 | |
| 0.13.2 | 41 / 7 | |
| 0.13.1 | 41 / 7 | |
| 0.13.0 | 41 / 7 | |
| 0.12.1 | 36 / 6 | |
| 0.12.0 | 36 / 6 | |
| 0.11.1 | 36 / 6 | |
| 0.11.0 | 36 / 6 | |
| 0.10.0 | 34 / 6 | |
| 0.9.7 | 34 / 6 | |
| 0.9.6 | 33 / 6 | |
| 0.9.5 | 33 / 6 | |
| 0.9.4 | 33 / 6 | |
| 0.9.3 | 33 / 6 | |
| 0.9.2 | 33 / 6 | |
| 0.9.1 | 33 / 6 | |
| 0.9.0 | 33 / 6 |
v0.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.