@cordisjs/boilerplate
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@cordisjs/plugin-sso-webauthn | AI (phantom-deps): Config-driven boilerplate; plugins declared not imported, same-org scope. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-database-sqlite | AI (phantom-deps): Boilerplate declares plugins for runtime config, not direct import. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-database-webui | AI (phantom-deps): Boilerplate declares plugins for runtime config, not direct import. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-server-webui | AI (phantom-deps): Boilerplate declares plugins for runtime config, not direct import. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-logger-webui | AI (phantom-deps): Boilerplate config-driven plugin list, not direct imports; expected pattern. | ai | |
| dependencies | unvetted-dep:@cordisjs/plugin-loader | AI (dependencies): Official same-org plugin loader used by the boilerplate. | ai | |
| dependencies | unvetted-dep:cordis | AI (dependencies): Core framework of this org's own boilerplate; expected dep. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-sso-oauth | AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-webui-sso | AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-sso-server | AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-sso-password | AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-sso | AI (phantom-deps): Config-driven plugin loader; same-org dep declared but loaded dynamically at runtime. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-logger-console | AI (phantom-deps): Config-driven plugin loader; same-org dep declared but loaded dynamically at runtime. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-server-acl | AI (phantom-deps): Config-driven plugin loader; same-org dep declared but loaded dynamically at runtime. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-database | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-notifier | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-cli-cordis | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:cordis | AI (phantom-deps): Boilerplate package; deps are config-referenced plugins, not JS imports. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-http-webui | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-loader-webui | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-http-socks | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-cli | AI (phantom-deps): Same as above; config-referenced plugin in cordis.yml boilerplate. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-env | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-hmr | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-http | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-group | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-timer | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-webui | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-loader | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-logger | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-market | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-server | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-include | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai | |
| phantom-deps | phantom-dep:@cordisjs/plugin-insight | AI (phantom-deps): Config-referenced plugin; boilerplate pattern. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.6.0 | 30 / 10 | |
| 0.5.13 | 30 / 10 | |
| 0.5.10 | 29 / 10 | |
| 0.5.9 | 30 / 10 | |
| 0.5.7 | 24 / 10 | |
| 0.5.6 | 24 / 10 | |
| 0.5.5 | 23 / 10 | |
| 0.5.3 | 23 / 10 | |
| 0.4.2 | 16 / 10 | |
| 0.4.1 | 16 / 10 |
v0.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.