← Home

@commercetools-frontend/create-mc-app

Create Merchant Center applications to quickly get up and running

29
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tdeekensemmenkocommercetools-admin

Keywords

javascriptfrontendreacttoolkit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): commercetools migrated to GitHub Actions CI/CD publishing with SLSA provenance; this is the expected new publisher for this org. ai
phantom-deps phantom-dep:@types/semver AI (phantom-deps): Type package loaded by convention, not directly imported; stable false positive. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Babel runtime loaded transitively by convention; stable false positive. ai
phantom-deps phantom-dep:@types/babel__core AI (phantom-deps): Type package loaded by convention; stable false positive. ai

Versions (showing 29 of 29)

Version Deps Published
27.8.0 12 / 2
27.7.0 12 / 2
27.6.3 12 / 2
27.6.2 11 / 2
27.6.1 11 / 2
27.6.0 11 / 2
27.5.4 11 / 2
27.5.3 11 / 2
27.5.2 11 / 2
27.5.1 11 / 2
27.5.0 11 / 2
27.4.2 11 / 2
27.4.1 11 / 2
27.4.0 11 / 2
27.3.0 11 / 2
27.2.0 11 / 2
27.1.0 11 / 2
27.0.0 11 / 2
26.1.0 11 / 2
26.0.2 11 / 2
26.0.1 11 / 2
26.0.0 11 / 2
25.2.0 11 / 2
25.1.0 11 / 2
25.0.0 11 / 2
24.13.0 11 / 2
24.12.0 11 / 2
24.11.0 11 / 2
24.10.0 11 / 2

v27.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v27.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.