@cubejs-backend/server-core
Cube.js base component to wire all backend components together
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:playground/assets/index-Dp9g9mH4.js | AI (source-diff): Network calls and dynamic code in playground bundle are standard React SPA patterns (fetch for modulepreload), not dropper behavior. | ai | |
| source-diff | obfuscated-file:playground/assets/index-Dp9g9mH4.js | AI (source-diff): Bundled React/Vite SPA for Cube.js playground UI; minified output is expected and consistent across versions. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fires in bundled playground CSS-in-JS asset; not malicious API obfuscation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation present; no material changes from prior version; established monorepo with 1160 published versions. | ai | |
| dependencies | unvetted-dep:@cubejs-backend/dotenv | AI (dependencies): Scoped @cubejs-backend dependency; part of the same Cube.js monorepo ecosystem, stable across versions. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): moment is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:codesandbox-import-utils | AI (phantom-deps): codesandbox-import-utils is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): semver is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package; README links to docs, no keywords is normal for internal packages. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 1.6.60 | 31 / 13 | |
| 1.6.59 | 31 / 13 | |
| 1.6.58 | 31 / 13 | |
| 1.6.57 | 31 / 13 | |
| 1.6.56 | 31 / 13 | |
| 1.6.55 | 31 / 13 | |
| 1.6.54 | 31 / 13 | |
| 1.6.53 | 31 / 13 | |
| 1.6.52 | 31 / 13 | |
| 1.6.51 | 31 / 13 | |
| 1.6.50 | 31 / 13 | |
| 1.6.49 | 31 / 13 | |
| 1.6.48 | 31 / 13 | |
| 1.6.47 | 31 / 13 | |
| 1.6.46 | 31 / 13 | |
| 1.6.45 | 31 / 13 | |
| 1.6.44 | 31 / 13 | |
| 1.6.43 | 31 / 13 | |
| 1.6.42 | 31 / 13 | |
| 1.6.41 | 31 / 13 | |
| 1.6.40 | 31 / 13 | |
| 1.6.39 | 31 / 13 | |
| 1.6.37 | 31 / 13 | |
| 1.6.36 | 31 / 13 | |
| 1.6.35 | 31 / 13 | |
| 1.6.34 | 31 / 13 | |
| 1.6.33 | 31 / 13 | |
| 1.6.32 | 31 / 13 | |
| 1.6.1 | 31 / 13 | |
| 1.6.0 | 31 / 13 | |
| 1.5.16 | 31 / 13 | |
| 1.5.15 | 31 / 13 | |
| 1.5.14 | 31 / 13 | |
| 1.5.13 | 31 / 13 |
v1.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.