@gooddata/app-toolkit
CLI with useful tools for creating and maintaining GoodData web applications.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| email-domain | unclaimed-email:rodri360.com | AI (email-domain): Long-established GoodData org package; stale maintainer email is a hygiene issue, not an active threat vector given CI publishing pattern. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Runtime dep for HTTP calls in CLI; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): Known implicit TypeScript runtime dependency; stable false positive. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Config-file loaded dep for CLI toolkit; stable false positive. | ai | |
| phantom-deps | phantom-dep:columnify | AI (phantom-deps): CLI output formatting dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:fast-glob | AI (phantom-deps): File-globbing dep used in build scripts; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/cli | AI (phantom-deps): Framework-scoped; loaded by convention in build pipeline. | ai | |
| phantom-deps | phantom-dep:strip-ansi | AI (phantom-deps): CLI utility dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): CLI toolkit; ora is a runtime dep used in scaffolding scripts, not directly imported in analyzed entry points. | ai | |
| phantom-deps | phantom-dep:webpack-cli | AI (phantom-deps): Build tooling dep loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Framework-scoped babel preset; loaded by convention. | ai | |
| phantom-deps | phantom-dep:webpack-dev-server | AI (phantom-deps): Dev server dep used in generated app configs; stable false positive. | ai | |
| phantom-deps | phantom-dep:@gooddata/sdk-model | AI (phantom-deps): Same org scope; used in generated scaffolding templates, not direct imports. | ai | |
| phantom-deps | phantom-dep:@babel/preset-typescript | AI (phantom-deps): Framework-scoped babel preset; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@gooddata/sdk-backend-tiger | AI (phantom-deps): Same org scope; used in generated scaffolding templates, not direct imports. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped; loaded by convention. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 11.40.0 | 24 / 27 | |
| 11.39.0 | 24 / 27 | |
| 11.38.0 | 24 / 27 | |
| 11.37.0 | 24 / 27 | |
| 11.36.0 | 24 / 27 | |
| 11.35.0 | 24 / 27 | |
| 11.34.0 | 24 / 27 | |
| 11.33.0 | 24 / 27 | |
| 11.32.0 | 24 / 27 | |
| 11.31.0 | 24 / 27 | |
| 11.30.0 | 24 / 27 | |
| 11.29.0 | 24 / 27 | |
| 11.28.0 | 24 / 27 | |
| 11.27.0 | 24 / 27 | |
| 11.26.0 | 24 / 27 | |
| 11.25.0 | 24 / 27 | |
| 11.24.0 | 24 / 27 | |
| 11.23.0 | 24 / 27 | |
| 11.22.0 | 24 / 27 | |
| 11.21.0 | 24 / 27 | |
| 11.20.0 | 24 / 27 | |
| 11.19.0 | 24 / 27 | |
| 11.18.0 | 24 / 27 | |
| 11.17.0 | 24 / 26 | |
| 11.16.0 | 24 / 26 | |
| 11.15.0 | 24 / 26 | |
| 11.14.0 | 24 / 26 | |
| 11.13.0 | 24 / 26 | |
| 11.12.0 | 24 / 26 | |
| 11.11.0 | 24 / 26 | |
| 11.10.0 | 24 / 26 | |
| 11.9.0 | 24 / 26 | |
| 11.8.0 | 24 / 26 | |
| 11.7.1 | 24 / 26 | |
| 11.7.0 | 24 / 26 | |
| 11.6.0 | 24 / 26 | |
| 11.5.0 | 24 / 26 | |
| 11.4.0 | 24 / 26 | |
| 11.3.0 | 24 / 28 | |
| 11.2.0 | 24 / 28 | |
| 11.1.0 | 24 / 28 | |
| 11.0.0 | 24 / 28 |
v11.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.35.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.34.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.33.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.31.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.30.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.29.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.28.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.27.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.26.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.25.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.24.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.23.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.22.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.21.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.20.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.19.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.18.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.17.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.16.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.15.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.13.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.12.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.11.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.10.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.9.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.8.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.1
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.6.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.5.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.4.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.3.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.2.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.1.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.0.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.