← Home

@datadog/datadog-ci-plugin-sarif

Datadog CI plugin for `sarif` commands

28
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

datadog

Keywords

datadogdatadog-ciplugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/bundle.js AI (source-diff): Official Datadog CI plugin; bundle.js is a rolldown-generated bundle with SLSA provenance, not malware. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling previously external runtime deps into dist/bundle.js. ai
provenance publisher-changed AI (provenance): Datadog publishes via GitHub Actions CI/CD with SLSA attestation; this is the expected publisher for this package. ai
phantom-deps phantom-dep:simple-git AI (phantom-deps): simple-git is a declared runtime dependency; phantom-dep heuristic false positive for this package. ai
source-diff encoded-string-file:dist/bundle.js AI (source-diff): Encoded string is the llhttp WASM binary bundled from undici; stable false positive for this package. ai

Versions (showing 28 of 28)

Version Deps Published
5.21.2 0 / 9
5.21.1 0 / 9
5.21.0 0 / 9
5.20.1 0 / 9
5.20.0 0 / 9
5.19.0 0 / 9
5.18.0 0 / 9
5.17.0 0 / 9
5.16.1 0 / 9
5.16.0 0 / 10
5.15.0 0 / 10
5.14.0 0 / 10
5.13.1 0 / 10
5.13.0 0 / 10
5.12.1 6 / 4
5.12.0 6 / 4
5.11.0 6 / 4
5.10.0 6 / 4
5.9.1 8 / 2
5.9.0 8 / 2
5.8.0 8 / 2
5.7.0 8 / 2
5.6.0 8 / 2
5.5.0 8 / 2
5.4.0 8 / 2
5.3.0 8 / 2
4.1.1 8 / 2
4.1.0 8 / 2

v5.21.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.21.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.20.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.