@itentialopensource/adapter-bmc_helix_itsm
This adapter integrates with system described as: bmc_helix_itsm
11
Versions
Apache-2.0
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jared.obrienjohnpolanskyzack.strulovitchitential-ciandyknaebelishitaprakash
Keywords
ItentialItential PlatformAutomationIntegrationAdapterITSMTestingBmcHelixItsmPre-Release
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established Itential org package; lack of Sigstore attestation is consistent across all versions. | ai | |
| dependencies | unvetted-dep:mocha-param | AI (dependencies): mocha-param is a test utility dependency; not a runtime risk for this adapter package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used for adapter tooling/troubleshooting utilities; consistent with Itential adapter framework. | ai | |
| phantom-deps | phantom-dep:ping | AI (phantom-deps): ping is a declared runtime dep used in adapter connectivity checks; phantom-dep heuristic false positive. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Itential adapter pattern; preinstall runs local setup.js, consistent across all 34 versions. | ai | |
| phantom-deps | phantom-dep:mocha-param | AI (phantom-deps): mocha-param used in test config files; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:prompts | AI (phantom-deps): prompts declared as runtime dep for interactive setup scripts; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require resolves a local path-joined file (adapterBase.js), not user input; stable pattern for this adapter. | ai |