@databricks/appkit
Build Databricks Apps faster with our brand-new Node.js + React SDK. Built for humans and AI.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Databricks org package published via GitHub Actions CI; individual maintainer removal reflects CI-managed publishing, not a takeover. | ai | |
| phantom-deps | phantom-dep:@standard-schema/spec | AI (phantom-deps): Schema spec package likely used as a type-only/peer dependency; stable false positive for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): js-yaml and get-port are established, widely-used packages with no known malicious history. | ai | |
| dependencies | unvetted-dep:@databricks/sdk-experimental | AI (dependencies): First-party Databricks SDK package; stable dependency for this package family. | ai | |
| dependencies | unvetted-dep:@databricks/lakebase | AI (dependencies): First-party Databricks package; stable dependency for this package family. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs a local node script for CLI setup; no network fetch or shell exec; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@types/semver | AI (phantom-deps): @types/semver is a type declaration package; not directly imported at runtime by convention. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.38.1 | 34 / 7 | |
| 0.34.1 | 34 / 7 | |
| 0.33.0 | 34 / 7 | |
| 0.31.0 | 33 / 6 | |
| 0.29.0 | 32 / 6 | |
| 0.27.0 | 32 / 5 | |
| 0.22.0 | 31 / 5 |
v0.38.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.