@directus/extensions-sdk
A toolkit to develop extensions to extend Directus
19
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
benhaynesrijkalexgaillard88
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Directus migrated to GitHub Actions CI publishing with SLSA attestation; this is a legitimate maintainer transition for the org. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation confirms CI/CD publish; Directus monorepo release cadence explains gaps. | ai | |
| dependencies | unvetted-dep:@directus/constants | AI (dependencies): Internal Directus monorepo package; stable dependency for this SDK. | ai | |
| dependencies | unvetted-dep:rollup-plugin-styler | AI (dependencies): Standard build tooling dependency for extension bundling; no malicious indicators. | ai | |
| phantom-deps | phantom-dep:vite | AI (phantom-deps): vite is a declared runtime dep used as a build tool; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): esbuild is a declared dep used as a runtime binary; known implicit dependency pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Directus monorepo sub-package; sparse README/no keywords is normal for internal SDK packages. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 18.0.1 | 26 / 7 | |
| 18.0.0 | 26 / 7 | |
| 17.1.4 | 26 / 7 | |
| 17.1.3 | 26 / 7 | |
| 17.1.2 | 26 / 7 | |
| 17.1.1 | 26 / 7 | |
| 17.1.0 | 26 / 7 | |
| 17.0.11 | 26 / 7 | |
| 17.0.10 | 26 / 7 | |
| 17.0.9 | 26 / 7 | |
| 17.0.8 | 26 / 7 | |
| 17.0.7 | 26 / 7 | |
| 17.0.6 | 26 / 7 | |
| 17.0.5 | 26 / 7 | |
| 17.0.4 | 26 / 7 | |
| 17.0.3 | 26 / 7 | |
| 17.0.2 | 26 / 7 | |
| 17.0.1 | 26 / 7 | |
| 17.0.0 | 26 / 7 |
v18.0.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.