@c8y/application
This package is used to scaffold a default application for Cumulocity IoT.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:rxjs | AI (phantom-deps): rxjs is a peer/transitive dep in Angular ecosystem; not directly imported in scaffold packages by design. | ai | |
| phantom-deps | phantom-dep:@c8y/style | AI (phantom-deps): Same-org sibling dep; loaded by convention in Cumulocity scaffold, not via direct import. | ai | |
| phantom-deps | phantom-dep:@c8y/client | AI (phantom-deps): Same-org sibling dep; loaded by convention in Cumulocity scaffold, not via direct import. | ai | |
| phantom-deps | phantom-dep:@angular/cdk | AI (phantom-deps): Framework-scoped Angular package loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:monaco-editor | AI (phantom-deps): Referenced in config files for lazy loading; not directly imported in scaffold source. | ai | |
| phantom-deps | phantom-dep:ngx-bootstrap | AI (phantom-deps): Referenced in config files; standard scaffold pattern for this package. | ai |
Versions (showing 51 of 222)
| Version | Deps | Published |
|---|---|---|
| 1024.5.1 | 10 / 2 | |
| 1024.2.4 | 10 / 2 | |
| 1024.1.8 | 10 / 2 | |
| 1024.1.6 | 10 / 2 | |
| 1024.1.5 | 10 / 2 | |
| 1024.0.0 | 10 / 2 | |
| 1023.97.8 | 9 / 2 | |
| 1023.97.7 | 9 / 2 | |
| 1023.97.4 | 9 / 2 | |
| 1023.97.3 | 9 / 2 | |
| 1023.96.0 | 9 / 2 | |
| 1023.92.0 | 9 / 2 | |
| 1023.90.1 | 9 / 2 | |
| 1023.88.4 | 9 / 2 | |
| 1023.88.2 | 9 / 2 | |
| 1023.88.1 | 9 / 2 | |
| 1023.85.1 | 9 / 2 | |
| 1023.83.4 | 8 / 2 | |
| 1023.83.3 | 8 / 2 | |
| 1023.83.2 | 8 / 2 | |
| 1023.82.8 | 8 / 2 | |
| 1023.82.4 | 8 / 2 | |
| 1023.82.3 | 8 / 2 | |
| 1023.82.2 | 8 / 2 | |
| 1023.82.1 | 8 / 2 | |
| 1023.82.0 | 8 / 2 | |
| 1023.81.3 | 8 / 2 | |
| 1023.81.2 | 8 / 2 | |
| 1023.80.2 | 8 / 2 | |
| 1023.80.0 | 8 / 2 | |
| 1023.79.1 | 8 / 2 | |
| 1023.78.7 | 8 / 2 | |
| 1023.78.5 | 8 / 2 | |
| 1023.78.4 | 8 / 2 | |
| 1023.78.1 | 8 / 2 | |
| 1023.77.1 | 8 / 2 | |
| 1023.76.0 | 8 / 2 | |
| 1023.75.1 | 8 / 2 | |
| 1023.71.1 | 8 / 2 | |
| 1023.70.0 | 8 / 2 | |
| 1023.68.7 | 8 / 2 | |
| 1023.68.6 | 8 / 2 | |
| 1023.68.3 | 8 / 2 | |
| 1023.68.0 | 8 / 2 | |
| 1023.67.0 | 8 / 2 | |
| 1023.66.4 | 8 / 2 | |
| 1023.66.3 | 8 / 2 | |
| 1023.65.2 | 8 / 2 | |
| 1023.65.1 | 8 / 2 | |
| 1023.65.0 | 8 / 2 | |
| 1023.64.2 | 8 / 2 |
v1024.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.96.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.