@c8y/devkit
Cumulocity Webpack Build Facade
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:zip-dir | AI (dependencies): Legitimate build utility for this webpack facade; stable across versions. | ai | |
| dependencies | unvetted-dep:JSONPath | AI (dependencies): Standard JSON querying library used in build tooling; no risk signal. | ai | |
| dependencies | unvetted-dep:babel-plugin-angularjs-annotate | AI (dependencies): Known Babel plugin for AngularJS DI annotation; consistent with this package's purpose. | ai | |
| provenance | no-provenance | AI (provenance): Published via GitHub Actions CI; provenance attestation absence is common for this ecosystem. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-optional-chaining | AI (phantom-deps): Framework-scoped babel plugin; loaded by convention. | ai | |
| phantom-deps | phantom-dep:file-loader | AI (phantom-deps): Webpack loader referenced in config files, not direct import — expected pattern. | ai | |
| phantom-deps | phantom-dep:html-loader | AI (phantom-deps): Webpack loader referenced in config files, not direct import — expected pattern. | ai | |
| phantom-deps | phantom-dep:babel-eslint | AI (phantom-deps): Referenced in config files; stable false positive for this build facade. | ai | |
| phantom-deps | phantom-dep:babel-loader | AI (phantom-deps): Webpack loader referenced in config files, not direct import — expected pattern. | ai | |
| phantom-deps | phantom-dep:style-loader | AI (phantom-deps): Webpack loader referenced in config files, not direct import — expected pattern. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): Framework-scoped babel tooling loaded by convention in build facade. | ai | |
| phantom-deps | phantom-dep:imports-loader | AI (phantom-deps): Webpack loader referenced in config files, not direct import — expected pattern. | ai | |
| npm-metadata | url-dep:angular-gettext-tools | AI (npm-metadata): Git URL is pinned to a specific commit SHA, not a mutable branch; risk is low and stable across versions. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Framework-scoped babel tooling loaded by convention in build facade. | ai | |
| phantom-deps | phantom-dep:@babel/eslint-parser | AI (phantom-deps): Framework-scoped babel tooling loaded by convention in build facade. | ai | |
| phantom-deps | phantom-dep:webpack-dev-middleware | AI (phantom-deps): Referenced in config files; stable false positive for this build facade. | ai | |
| phantom-deps | phantom-dep:webpack-hot-middleware | AI (phantom-deps): Referenced in config files; stable false positive for this build facade. | ai | |
| phantom-deps | phantom-dep:@babel/helper-plugin-utils | AI (phantom-deps): Framework-scoped babel tooling loaded by convention in build facade. | ai | |
| phantom-deps | phantom-dep:babel-plugin-angularjs-annotate | AI (phantom-deps): Referenced in config files; stable false positive for this build facade. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-syntax-dynamic-import | AI (phantom-deps): Framework-scoped babel tooling loaded by convention in build facade. | ai | |
| phantom-deps | phantom-dep:postcss-loader | AI (phantom-deps): Webpack loader referenced in config files, not direct import — expected pattern. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Build facade; webpack/babel tools loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@babel/cli | AI (phantom-deps): Framework-scoped babel tooling loaded by convention in build facade. | ai | |
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): Webpack loader referenced in config files, not direct import — expected pattern. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped babel tooling loaded by convention in build facade. | ai |
Versions (showing 51 of 221)
| Version | Deps | Published |
|---|---|---|
| 1024.5.1 | 48 / 2 | |
| 1024.2.4 | 48 / 2 | |
| 1024.1.8 | 48 / 2 | |
| 1024.1.6 | 48 / 2 | |
| 1024.1.5 | 48 / 2 | |
| 1024.0.0 | 48 / 2 | |
| 1023.97.8 | 48 / 2 | |
| 1023.97.7 | 48 / 2 | |
| 1023.97.4 | 48 / 2 | |
| 1023.97.3 | 48 / 2 | |
| 1023.96.0 | 48 / 2 | |
| 1023.92.0 | 48 / 2 | |
| 1023.90.1 | 48 / 2 | |
| 1023.88.4 | 48 / 2 | |
| 1023.88.2 | 48 / 2 | |
| 1023.88.1 | 48 / 2 | |
| 1023.85.1 | 48 / 2 | |
| 1023.83.4 | 48 / 2 | |
| 1023.83.3 | 48 / 2 | |
| 1023.83.2 | 48 / 2 | |
| 1023.82.8 | 48 / 2 | |
| 1023.82.4 | 48 / 2 | |
| 1023.82.3 | 48 / 2 | |
| 1023.82.2 | 48 / 2 | |
| 1023.82.1 | 48 / 2 | |
| 1023.82.0 | 48 / 2 | |
| 1023.81.3 | 48 / 2 | |
| 1023.81.2 | 48 / 2 | |
| 1023.80.2 | 48 / 2 | |
| 1023.80.0 | 48 / 2 | |
| 1023.79.1 | 48 / 2 | |
| 1023.78.7 | 48 / 2 | |
| 1023.78.5 | 48 / 2 | |
| 1023.78.4 | 48 / 2 | |
| 1023.78.1 | 48 / 2 | |
| 1023.77.1 | 48 / 2 | |
| 1023.76.0 | 48 / 2 | |
| 1023.75.1 | 48 / 2 | |
| 1023.71.1 | 47 / 4 | |
| 1023.70.0 | 47 / 4 | |
| 1023.68.7 | 47 / 4 | |
| 1023.68.6 | 47 / 4 | |
| 1023.68.3 | 47 / 4 | |
| 1023.68.0 | 47 / 4 | |
| 1023.67.0 | 47 / 4 | |
| 1023.66.4 | 47 / 4 | |
| 1023.66.3 | 47 / 4 | |
| 1023.65.2 | 47 / 4 | |
| 1023.65.1 | 47 / 4 | |
| 1023.64.1 | 47 / 4 | |
| 1023.63.1 | 47 / 4 |
v1024.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.1.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1024.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.97.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1023.96.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.