← Home

@cordisjs/boilerplate

10
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

shigma

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@cordisjs/plugin-sso-webauthn AI (phantom-deps): Config-driven boilerplate; plugins declared not imported, same-org scope. ai
phantom-deps phantom-dep:@cordisjs/plugin-database-sqlite AI (phantom-deps): Boilerplate declares plugins for runtime config, not direct import. ai
phantom-deps phantom-dep:@cordisjs/plugin-database-webui AI (phantom-deps): Boilerplate declares plugins for runtime config, not direct import. ai
phantom-deps phantom-dep:@cordisjs/plugin-server-webui AI (phantom-deps): Boilerplate declares plugins for runtime config, not direct import. ai
phantom-deps phantom-dep:@cordisjs/plugin-logger-webui AI (phantom-deps): Boilerplate config-driven plugin list, not direct imports; expected pattern. ai
dependencies unvetted-dep:@cordisjs/plugin-loader AI (dependencies): Official same-org plugin loader used by the boilerplate. ai
dependencies unvetted-dep:cordis AI (dependencies): Core framework of this org's own boilerplate; expected dep. ai
phantom-deps phantom-dep:@cordisjs/plugin-sso-oauth AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. ai
phantom-deps phantom-dep:@cordisjs/plugin-webui-sso AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. ai
phantom-deps phantom-dep:@cordisjs/plugin-sso-server AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. ai
phantom-deps phantom-dep:@cordisjs/plugin-sso-password AI (phantom-deps): Same-org plugin loaded dynamically via plugin-loader, not imported directly. ai
phantom-deps phantom-dep:@cordisjs/plugin-sso AI (phantom-deps): Config-driven plugin loader; same-org dep declared but loaded dynamically at runtime. ai
phantom-deps phantom-dep:@cordisjs/plugin-logger-console AI (phantom-deps): Config-driven plugin loader; same-org dep declared but loaded dynamically at runtime. ai
phantom-deps phantom-dep:@cordisjs/plugin-server-acl AI (phantom-deps): Config-driven plugin loader; same-org dep declared but loaded dynamically at runtime. ai
phantom-deps phantom-dep:@cordisjs/plugin-database AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-notifier AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-cli-cordis AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:cordis AI (phantom-deps): Boilerplate package; deps are config-referenced plugins, not JS imports. Stable pattern for this package. ai
phantom-deps phantom-dep:@cordisjs/plugin-http-webui AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-loader-webui AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-http-socks AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-cli AI (phantom-deps): Same as above; config-referenced plugin in cordis.yml boilerplate. ai
phantom-deps phantom-dep:@cordisjs/plugin-env AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-hmr AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-http AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-group AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-timer AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-webui AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-loader AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-logger AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-market AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-server AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-include AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai
phantom-deps phantom-dep:@cordisjs/plugin-insight AI (phantom-deps): Config-referenced plugin; boilerplate pattern. ai

Versions (showing 10 of 10)

Version Deps Published
0.6.0 30 / 10
0.5.13 30 / 10
0.5.10 29 / 10
0.5.9 30 / 10
0.5.7 24 / 10
0.5.6 24 / 10
0.5.5 23 / 10
0.5.3 23 / 10
0.4.2 16 / 10
0.4.1 16 / 10

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.