@databricks/appkit
Build Databricks Apps faster with our brand-new Node.js + React SDK. Built for humans and AI.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:zod-to-ts | AI (phantom-deps): Config-referenced, not a real issue. | ai | |
| dependencies | unvetted-dep:obug | AI (dependencies): Small logging utility dep, no malicious behavior observed. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Consistent with active monorepo release cadence, not injected code. | ai | |
| provenance | no-provenance | AI (provenance): Unchanged provenance vs prior approved version; CI publisher. | ai | |
| phantom-deps | phantom-dep:drizzle-orm | AI (phantom-deps): Used via config/type references, well-known ORM, not malicious. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Databricks org package published via GitHub Actions CI; individual maintainer removal reflects CI-managed publishing, not a takeover. | ai | |
| phantom-deps | phantom-dep:@standard-schema/spec | AI (phantom-deps): Schema spec package likely used as a type-only/peer dependency; stable false positive for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): js-yaml and get-port are established, widely-used packages with no known malicious history. | ai | |
| dependencies | unvetted-dep:@databricks/sdk-experimental | AI (dependencies): First-party Databricks SDK package; stable dependency for this package family. | ai | |
| dependencies | unvetted-dep:@databricks/lakebase | AI (dependencies): First-party Databricks package; stable dependency for this package family. | ai | |
| phantom-deps | phantom-dep:@types/semver | AI (phantom-deps): @types/semver is a type declaration package; not directly imported at runtime by convention. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs a local node script for CLI setup; no network fetch or shell exec; stable pattern for this package. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 0.44.0 | 36 / 7 | |
| 0.41.6 | 35 / 7 | |
| 0.38.1 | 34 / 7 | |
| 0.36.0 | 35 / 7 | |
| 0.34.1 | 34 / 7 | |
| 0.33.0 | 34 / 7 | |
| 0.31.0 | 33 / 6 | |
| 0.29.0 | 32 / 6 | |
| 0.28.0 | 32 / 6 | |
| 0.27.0 | 32 / 5 | |
| 0.26.0 | 31 / 5 | |
| 0.25.1 | 31 / 5 | |
| 0.23.0 | 31 / 5 | |
| 0.22.0 | 31 / 5 | |
| 0.20.2 | 31 / 5 | |
| 0.18.0 | 31 / 5 | |
| 0.17.0 | 31 / 5 | |
| 0.14.0 | 30 / 5 | |
| 0.13.0 | 30 / 5 | |
| 0.4.0 | 26 / 4 | |
| 0.1.1 | 21 / 4 |
v0.44.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.