← Home

@c8y/devicemanagement

This package is used to scaffold a Device Management application for Cumulocity IoT.

8
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

c8y

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:angular AI (dependencies): Standard AngularJS peer dep for Angular hybrid app; stable pattern across all @c8y/* package versions. ai
dependencies unvetted-dep:@angular/upgrade AI (dependencies): Standard Angular upgrade module for AngularJS hybrid; expected dependency for this package family. ai
phantom-deps phantom-dep:@c8y/html-repo AI (phantom-deps): Same-org @c8y/* package; declared as peer/transitive dep, not directly imported by convention. ai
phantom-deps phantom-dep:angular AI (phantom-deps): AngularJS loaded by convention/config in hybrid Angular app; not directly imported in source. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): rxjs is a framework-level dep used transitively; phantom-dep false positive for Angular packages. ai
phantom-deps phantom-dep:@c8y/style AI (phantom-deps): Same-org @c8y/* package; declared as peer/transitive dep, not directly imported by convention. ai
phantom-deps phantom-dep:ngx-bootstrap AI (phantom-deps): Referenced in config files; loaded by module convention, not direct import. ai
phantom-deps phantom-dep:monaco-editor AI (phantom-deps): Referenced in config files; loaded by convention/lazy loading, not direct import. ai
provenance no-provenance AI (provenance): GitHub Actions publisher for an enterprise vendor; lack of Sigstore attestation is common and not a risk signal here. ai
phantom-deps phantom-dep:@angular/cdk AI (phantom-deps): Framework-scoped package loaded by convention in Angular apps; stable false positive. ai
phantom-deps phantom-dep:@c8y/client AI (phantom-deps): Same-org @c8y/* package; declared as peer/transitive dep, not directly imported by convention. ai

Versions (showing 8 of 8)

Version Deps Published
1023.80.0 12 / 2
1023.79.1 12 / 2
1023.78.7 12 / 2
1023.78.5 12 / 2
1023.76.0 12 / 2
1023.14.153 12 / 2
1023.14.152 12 / 2
1023.14.132 12 / 2

v1023.80.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1023.79.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1023.78.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1023.78.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1023.14.153

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1023.14.152

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1023.14.132

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.