@itentialopensource/adapter-salesforce
This adapter integrates with system Salesforce
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Established Itential adapter with 43 versions and trusted publisher track record; dormancy consistent with maintenance cadence. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads adapterBase.js via path.join — deterministic path construction, not user-controlled input. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): execSync/spawnSync used for adapter connectivity/troubleshooting utilities; consistent with documented adapter framework. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Itential adapter pattern; setup.js is a standard hook across all adapter versions in this ecosystem. | ai | |
| phantom-deps | phantom-dep:prompts | AI (phantom-deps): prompts used in setup/utility scripts, not main adapter code — stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:mocha-param | AI (phantom-deps): mocha-param referenced in test config files; stable false positive for this adapter package. | ai | |
| phantom-deps | phantom-dep:ping | AI (phantom-deps): ping is a declared runtime dep used in config/connectivity scripts, not directly imported in main code. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 1.0.2 | 15 / 6 | |
| 1.0.1 | 15 / 6 | |
| 1.0.0 | 15 / 6 | |
| 0.15.1 | 15 / 6 | |
| 0.15.0 | 15 / 6 | |
| 0.14.0 | 15 / 6 | |
| 0.13.0 | 15 / 6 |
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.15.1
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.15.0
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.14.0
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.0
2 findingsScript: node utils/setup.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.