← Home

@coveo/quantic

A Salesforce Lightning Web Component (LWC) library for building modern UIs interfacing with the Coveo platform

22
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

oa-npmcoveo

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): Docs/build artifacts growth for an established SFDX component library. ai
publish-pattern new-deps-added AI (publish-pattern): coveo.analytics is a first-party Coveo dependency. ai
maintainer-change maintainer-added AI (maintainer-change): Move to trusted CI/CD publisher with provenance, not a takeover. ai
maintainer-change maintainer-removed AI (maintainer-change): Coveo migrated publishing to GitHub Actions CI; removal of human maintainers is expected org-level automation change. ai
provenance missing-githead AI (provenance): Package has SLSA provenance attestation; missing gitHead is a minor CI config change, not a supply chain risk for this established package. ai
publish-pattern dormant-publish AI (publish-pattern): Coveo org package with SLSA provenance; CI/CD publisher and no material changes from prior version. ai
install-scripts install-script:preinstall AI (install-scripts): Runs local check-sfdx-project.js; standard SFDX project validation, stable for this Salesforce LWC package. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Listed as runtime dep; used in LWC components via config, not direct JS import — false positive for this package. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Listed as runtime dep; used in LWC components via config, not direct JS import — false positive for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): Fires inside bundled headless.js UMD wrapper — standard module pattern, not a security concern. ai
install-scripts install-script:postinstall AI (install-scripts): Runs local setup-quantic.js; documented Salesforce LWC setup step, stable for this package. ai

Versions (showing 22 of 22)

Version Deps Published
3.38.0 5 / 23
3.37.10 5 / 23
3.37.9 5 / 23
3.37.8 5 / 23
3.37.7 5 / 23
3.37.6 5 / 23
3.37.4 5 / 23
3.37.3 5 / 23
3.37.2 5 / 24
3.37.1 5 / 23
3.33.1 5 / 23
3.30.1 5 / 30
3.29.7 5 / 29
3.29.5 5 / 29
3.28.1 5 / 29
3.26.1 5 / 30
3.23.0 5 / 30
3.22.2 5 / 30
3.22.0 5 / 30
3.21.1 5 / 30
3.21.0 5 / 30
3.20.1 5 / 30

v3.33.1

3 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: pixhel.

INFO Publisher changed: npmcoveo → pixhel (on 2025-10-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (pixhel) than the most recent previously approved version (npmcoveo) on 2025-10-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.