@cedarjs/internal
27
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
tobbe
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are established GraphQL/codegen tooling matching package's purpose. | ai | |
| provenance | no-provenance | AI (provenance): Common for npm packages; not a blocker for established monorepo. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal monorepo package; missing description is expected. | ai | |
| phantom-deps | phantom-dep:@babel/runtime-corejs3 | AI (phantom-deps): Babel runtime; framework-scoped, loaded by convention. | ai | |
| phantom-deps | phantom-dep:core-js | AI (phantom-deps): Runtime polyfill; stable implicit dependency for this package. | ai | |
| dependencies | unvetted-dep:@sdl-codegen/node | AI (dependencies): Legitimate SDL codegen tooling consistent with this package's GraphQL code generation purpose. | ai | |
| dependencies | unvetted-dep:@graphql-codegen/typescript-react-apollo | AI (dependencies): Standard graphql-codegen plugin; consistent with this package's codegen toolchain. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-typescript | AI (phantom-deps): Framework-scoped Babel plugin loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typed-document-node | AI (phantom-deps): Codegen plugin referenced by config, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:rimraf | AI (phantom-deps): Used in build scripts, not runtime imports; stable false positive for this build-tool package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal framework package; sparse README and no keywords are expected for monorepo sub-packages. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typescript-react-apollo | AI (phantom-deps): Codegen plugin referenced by config; stable false positive. | ai | |
| phantom-deps | phantom-dep:ts-node | AI (phantom-deps): Referenced in config/tooling context, not a runtime import. | ai | |
| phantom-deps | phantom-dep:deepmerge | AI (phantom-deps): Declared dep used via config convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:systeminformation | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on this framework package. | ai | |
| phantom-deps | phantom-dep:@graphql-tools/documents | AI (phantom-deps): Declared dep; used indirectly via codegen pipeline. | ai | |
| phantom-deps | phantom-dep:string-env-interpolation | AI (phantom-deps): Declared dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-react-jsx | AI (phantom-deps): Framework-scoped Babel plugin loaded by convention, not direct import. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 5.0.4 | 49 / 6 | |
| 5.0.0 | 49 / 6 | |
| 4.1.0 | 42 / 7 | |
| 4.0.0 | 40 / 7 | |
| 3.1.1 | 37 / 7 | |
| 3.1.0 | 37 / 7 | |
| 3.0.0 | 37 / 7 | |
| 2.8.1 | 38 / 7 | |
| 2.8.0 | 38 / 7 | |
| 2.7.0 | 38 / 7 | |
| 2.6.0 | 38 / 7 | |
| 2.5.1 | 38 / 7 | |
| 2.5.0 | 38 / 7 | |
| 2.4.1 | 38 / 7 | |
| 2.4.0 | 38 / 7 | |
| 2.3.0 | 38 / 7 | |
| 2.2.1 | 38 / 7 | |
| 2.1.1 | 39 / 8 | |
| 2.1.0 | 39 / 8 | |
| 2.0.3 | 39 / 8 | |
| 2.0.2 | 39 / 8 | |
| 2.0.1 | 39 / 8 | |
| 2.0.0 | 39 / 8 | |
| 1.1.2 | 39 / 8 | |
| 1.1.1 | 39 / 8 | |
| 1.1.0 | 39 / 8 | |
| 1.0.0 | 39 / 8 |
v5.0.4
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.