← Home

@commercetools-frontend/sentry

29
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tdeekensemmenkocommercetools-admin

Keywords

javascriptfrontendreacttoolkit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with org-wide CI/CD migration for commercetools packages. ai
phantom-deps phantom-dep:prop-types AI (phantom-deps): Framework-convention peer dep in a React library; stable false positive for this package. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Type-only framework dep; stable false positive for this package. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Babel runtime injected by transpiler; stable false positive for this package. ai
phantom-deps phantom-dep:@types/prop-types AI (phantom-deps): Type-only dep; stable false positive for this package. ai
phantom-deps phantom-dep:@commercetools-frontend/constants AI (phantom-deps): Same-org monorepo sibling; stable false positive for this package. ai

Versions (showing 29 of 29)

Version Deps Published
27.8.0 10 / 6
27.7.0 10 / 6
27.6.3 10 / 6
27.6.2 10 / 6
27.6.1 10 / 6
27.6.0 10 / 6
27.5.4 10 / 6
27.5.3 10 / 6
27.5.2 10 / 6
27.5.1 10 / 6
27.5.0 10 / 6
27.4.2 10 / 6
27.4.1 10 / 6
27.4.0 10 / 6
27.3.0 10 / 6
27.2.0 10 / 6
27.1.0 10 / 6
27.0.0 10 / 6
26.1.0 10 / 6
26.0.2 10 / 6
26.0.1 10 / 6
26.0.0 10 / 6
25.2.0 10 / 6
25.1.0 10 / 6
25.0.0 10 / 6
24.13.0 10 / 6
24.12.0 10 / 6
24.11.0 10 / 6
24.10.0 10 / 6

v27.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v27.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.