@coveo/quantic
A Salesforce Lightning Web Component (LWC) library for building modern UIs interfacing with the Coveo platform
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Docs/build artifacts growth for an established SFDX component library. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): coveo.analytics is a first-party Coveo dependency. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Move to trusted CI/CD publisher with provenance, not a takeover. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Coveo migrated publishing to GitHub Actions CI; removal of human maintainers is expected org-level automation change. | ai | |
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation; missing gitHead is a minor CI config change, not a supply chain risk for this established package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Coveo org package with SLSA provenance; CI/CD publisher and no material changes from prior version. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Runs local check-sfdx-project.js; standard SFDX project validation, stable for this Salesforce LWC package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Listed as runtime dep; used in LWC components via config, not direct JS import — false positive for this package. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Listed as runtime dep; used in LWC components via config, not direct JS import — false positive for this package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Fires inside bundled headless.js UMD wrapper — standard module pattern, not a security concern. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs local setup-quantic.js; documented Salesforce LWC setup step, stable for this package. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 3.38.0 | 5 / 23 | |
| 3.37.10 | 5 / 23 | |
| 3.37.9 | 5 / 23 | |
| 3.37.8 | 5 / 23 | |
| 3.37.7 | 5 / 23 | |
| 3.37.6 | 5 / 23 | |
| 3.37.4 | 5 / 23 | |
| 3.37.3 | 5 / 23 | |
| 3.37.2 | 5 / 24 | |
| 3.37.1 | 5 / 23 | |
| 3.33.1 | 5 / 23 | |
| 3.30.1 | 5 / 30 | |
| 3.29.7 | 5 / 29 | |
| 3.29.5 | 5 / 29 | |
| 3.28.1 | 5 / 29 | |
| 3.26.1 | 5 / 30 | |
| 3.23.0 | 5 / 30 | |
| 3.22.2 | 5 / 30 | |
| 3.22.0 | 5 / 30 | |
| 3.21.1 | 5 / 30 | |
| 3.21.0 | 5 / 30 | |
| 3.20.1 | 5 / 30 |
v3.33.1
3 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: pixhel.
This version was published by a different npm account (pixhel) than the most recent previously approved version (npmcoveo) on 2025-10-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.