← Home

@cyclonedx/webpack-plugin

11
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sspringetteoftedalcoderpatroscyclonedx-automationjkowalleck

Keywords

webpackpluginwebpack-pluginCycloneDXbill-of-materialsBOMsoftware-bill-of-materialsSBOMinventorycomponentdependencypackage-urlPURLSPDX

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:spdx-expression-parse AI (dependencies): spdx-expression-parse is a well-known SPDX parsing library; appropriate for this SBOM tooling package. ai
provenance publisher-changed AI (provenance): Publisher is GitHub Actions CI/CD for the official CycloneDX org repo; automated publishing is expected. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms legitimate CI/CD origin; dormancy alone is not disqualifying for this established OWASP project. ai
publish-pattern new-deps-added AI (publish-pattern): packageurl-js and spdx-expression-parse are well-known SBOM ecosystem libs appropriate for this package's purpose. ai
phantom-deps phantom-dep:xmlbuilder2 AI (phantom-deps): xmlbuilder2 is a declared runtime dependency in package.json; phantom-dep heuristic is a false positive here. ai

Versions (showing 11 of 11)

Version Deps Published
5.3.2 5 / 9
5.3.1 5 / 9
5.3.0 5 / 9
5.2.4 3 / 8
5.2.3 3 / 8
5.2.2 3 / 8
5.2.1 3 / 8
5.2.0 3 / 8
5.1.1 3 / 8
5.1.0 3 / 8
5.0.1 3 / 8

v5.3.2

2 findings
HIGH Publisher changed: cyclonedx-automation → GitHub Actions (on 2026-03-19) provenance

This version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.1

2 findings
HIGH Publisher changed: cyclonedx-automation → GitHub Actions (on 2026-03-09) provenance

This version was published by a different npm account than previous versions on 2026-03-09. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.0

2 findings
HIGH Publisher changed: cyclonedx-automation → GitHub Actions (on 2026-03-04) provenance

This version was published by a different npm account than previous versions on 2026-03-04. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.