← Home

@jayree/sfdx-plugin-org

A Salesforce CLI plugin containing commands to configure State and Country/Territory Picklists and other org settings.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jayree

Keywords

orgconfigurestatecountryterritorypicklistssfdxsfdx-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Package consistently published via GitHub Actions CI with SLSA attestation; jayree→GitHub Actions is expected automation pattern. ai
dependencies unvetted-dep:tabletojson AI (dependencies): Legitimate HTML-table parsing dep used by this Salesforce CLI plugin; stable across versions. ai
dependencies unvetted-dep:@jayree/changelog AI (dependencies): First-party changelog dep from same author; stable across versions. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive for this package. ai
phantom-deps phantom-dep:enquirer AI (phantom-deps): enquirer is referenced via @listr2/prompt-adapter-enquirer and config files; stable false positive. ai

Versions (showing 100 of 134)

Version Deps Published
1.2.182 22 / 19
1.2.181 22 / 19
1.2.180 22 / 19
1.2.179 22 / 19
1.2.178 22 / 19
1.2.177 22 / 19
1.2.176 22 / 19
1.2.175 22 / 19
1.2.174 22 / 19
1.2.173 22 / 19
1.2.172 22 / 19
1.2.171 22 / 19
1.2.170 22 / 19
1.2.169 22 / 19
1.2.168 22 / 19
1.2.167 22 / 19
1.2.166 22 / 19
1.2.165 22 / 19
1.2.164 22 / 19
1.2.163 22 / 19
1.2.162 22 / 19
1.2.161 22 / 19
1.2.160 22 / 19
1.2.159 22 / 19
1.2.158 22 / 19
1.2.157 22 / 19
1.2.156 22 / 19
1.2.155 22 / 19
1.2.154 22 / 19
1.2.153 22 / 19
1.2.152 22 / 19
1.2.151 22 / 19
1.2.150 22 / 19
1.2.149 22 / 19
1.2.148 22 / 19
1.2.147 22 / 19
1.2.146 22 / 19
1.2.145 22 / 19
1.2.144 22 / 19
1.2.143 22 / 19
1.2.142 22 / 19
1.2.141 22 / 19
1.2.140 22 / 19
1.2.139 22 / 19
1.2.138 22 / 19
1.2.137 22 / 19
1.2.136 22 / 19
1.2.135 22 / 19
1.2.134 22 / 19
1.2.133 22 / 19
1.2.132 22 / 19
1.2.131 22 / 19
1.2.130 22 / 19
1.2.129 22 / 19
1.2.128 22 / 19
1.2.127 22 / 19
1.2.126 22 / 19
1.2.125 22 / 19
1.2.124 22 / 19
1.2.123 22 / 19
1.2.122 22 / 19
1.2.121 22 / 19
1.2.120 22 / 19
1.2.119 22 / 19
1.2.118 22 / 19
1.2.117 22 / 19
1.2.116 22 / 19
1.2.115 22 / 19
1.2.114 22 / 19
1.2.113 22 / 19
1.2.112 22 / 19
1.2.111 22 / 19
1.2.110 22 / 19
1.2.109 22 / 19
1.2.108 22 / 19
1.2.107 22 / 19
1.2.106 22 / 19
1.2.105 22 / 19
1.2.104 22 / 19
1.2.103 22 / 19
1.2.102 22 / 19
1.2.101 22 / 19
1.2.100 22 / 19
1.2.99 22 / 19
1.2.98 22 / 19
1.2.97 22 / 19
1.2.96 22 / 19
1.2.95 22 / 19
1.2.94 22 / 19
1.2.93 22 / 19
1.2.92 22 / 19
1.2.91 22 / 19
1.2.90 22 / 19
1.2.89 22 / 19
1.2.88 22 / 19
1.2.87 22 / 19
1.2.86 22 / 19
1.2.85 22 / 19
1.2.84 22 / 19
1.2.83 22 / 19
Showing 100 of 134 Next page →

v1.2.182

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.181

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.180

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.179

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.111

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.110

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.109

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.108

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.107

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.106

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.105

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.104

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.103

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.102

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.101

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.100

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.99

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.98

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.97

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.96

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.95

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.94

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.93

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.92

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.91

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.90

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.89

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.88

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.87

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.86

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.85

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.84

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.83

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.