← Home

@datadog/datadog-ci-plugin-sbom

Datadog CI plugin for `sbom` commands

28
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

datadog

Keywords

datadogdatadog-ciplugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/bundle.js AI (source-diff): Base64 WASM blob for undici's llhttp; standard in bundled Node.js HTTP libraries. ai
provenance publisher-changed AI (provenance): DataDog org publishes via GitHub Actions CI/CD; SLSA attestation confirms legitimate automated publishing pipeline. ai
source-diff net-exec-file:dist/bundle.js AI (source-diff): bundle.js is a rolldown-bundled artifact from the official DataDog repo; network calls are part of the CI plugin's documented functionality. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling previously external runtime deps (axios, ajv, etc.) into dist/bundle.js. ai
dependencies unvetted-dep:packageurl-js AI (dependencies): packageurl-js is a standard PURL parsing library; benign and appropriate for an SBOM plugin. ai

Versions (showing 28 of 28)

Version Deps Published
5.21.1 0 / 8
5.21.0 0 / 8
5.20.1 0 / 8
5.20.0 0 / 8
5.19.0 0 / 8
5.18.0 0 / 8
5.17.0 0 / 8
5.16.1 0 / 8
5.16.0 0 / 8
5.15.0 0 / 8
5.14.0 0 / 8
5.13.1 0 / 8
5.13.0 0 / 8
5.12.1 5 / 3
5.12.0 5 / 3
5.11.0 5 / 3
5.10.0 5 / 3
5.9.1 7 / 1
5.9.0 7 / 1
5.8.0 7 / 1
5.7.0 7 / 1
5.6.0 7 / 1
5.5.0 7 / 1
5.4.0 7 / 1
5.3.0 7 / 1
5.0.0 7 / 1
4.1.1 7 / 1
4.1.0 7 / 1

v5.21.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.20.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.