← Home

@c8y/devicemanagement

This package is used to scaffold a Device Management application for Cumulocity IoT.

14
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

c8y

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:gridstack AI (phantom-deps): Config-referenced UI library; stable pattern for this package. ai
publish-pattern new-deps-added AI (publish-pattern): @angular/animations is an official Angular package; addition is consistent with Angular app scaffolding. ai
phantom-deps phantom-dep:@angular/animations AI (phantom-deps): Framework-scoped Angular package loaded by convention; stable false positive for this package. ai
dependencies unvetted-dep:angular AI (dependencies): Standard AngularJS peer dep for Angular hybrid app; stable pattern across all @c8y/* package versions. ai
dependencies unvetted-dep:@angular/upgrade AI (dependencies): Standard Angular upgrade module for AngularJS hybrid; expected dependency for this package family. ai
phantom-deps phantom-dep:@angular/cdk AI (phantom-deps): Framework-scoped package loaded by convention in Angular apps; stable false positive. ai
phantom-deps phantom-dep:ngx-bootstrap AI (phantom-deps): Referenced in config files; loaded by module convention, not direct import. ai
phantom-deps phantom-dep:@c8y/style AI (phantom-deps): Same-org @c8y/* package; declared as peer/transitive dep, not directly imported by convention. ai
provenance no-provenance AI (provenance): GitHub Actions publisher for an enterprise vendor; lack of Sigstore attestation is common and not a risk signal here. ai
phantom-deps phantom-dep:monaco-editor AI (phantom-deps): Referenced in config files; loaded by convention/lazy loading, not direct import. ai
phantom-deps phantom-dep:@c8y/client AI (phantom-deps): Same-org @c8y/* package; declared as peer/transitive dep, not directly imported by convention. ai
phantom-deps phantom-dep:@c8y/html-repo AI (phantom-deps): Same-org @c8y/* package; declared as peer/transitive dep, not directly imported by convention. ai
phantom-deps phantom-dep:angular AI (phantom-deps): AngularJS loaded by convention/config in hybrid Angular app; not directly imported in source. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): rxjs is a framework-level dep used transitively; phantom-dep false positive for Angular packages. ai

Versions (showing 14 of 14)

Version Deps Published
1024.0.0 15 / 2
1023.82.1 12 / 2
1023.80.0 12 / 2
1023.79.1 12 / 2
1023.78.7 12 / 2
1023.78.5 12 / 2
1023.76.0 12 / 2
1023.67.0 12 / 2
1023.14.174 13 / 2
1023.14.171 12 / 2
1023.14.162 12 / 2
1023.14.153 12 / 2
1023.14.152 12 / 2
1023.14.132 12 / 2

v1024.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.