← Home

@jayree/sfdx-plugin-source

A Salesforce CLI plugin containing commands to generate and compare sfdx source snapshot files or manipulate local source tracking.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jayree

Keywords

sourcesnapshotsourcetrackingsfdxsfdx-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Consistent across all versions of this package; publisher has 30 approved packages without provenance. ai
dependencies unvetted-dep:@jayree/changelog AI (dependencies): Same-author first-party dependency; stable pattern across all versions of this package. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a declared runtime dep used implicitly by TypeScript compilation output; stable false positive for this package. ai
phantom-deps phantom-dep:fast-xml-parser AI (phantom-deps): Declared in package.json and referenced in config; indirect usage pattern is stable for this package. ai

Versions (showing 100 of 123)

Version Deps Published
1.3.178 16 / 18
1.3.177 16 / 18
1.3.176 16 / 18
1.3.175 16 / 18
1.3.174 16 / 18
1.3.173 16 / 18
1.3.172 16 / 18
1.3.171 16 / 18
1.3.170 16 / 18
1.3.169 16 / 18
1.3.168 16 / 18
1.3.167 16 / 18
1.3.166 16 / 18
1.3.165 16 / 18
1.3.164 16 / 18
1.3.163 16 / 18
1.3.162 16 / 18
1.3.161 16 / 18
1.3.160 16 / 18
1.3.159 16 / 18
1.3.158 16 / 18
1.3.157 16 / 18
1.3.156 16 / 18
1.3.155 16 / 18
1.3.154 16 / 18
1.3.153 16 / 18
1.3.152 16 / 18
1.3.151 16 / 18
1.3.150 16 / 18
1.3.149 16 / 18
1.3.148 16 / 18
1.3.147 16 / 18
1.3.146 16 / 18
1.3.145 16 / 18
1.3.144 16 / 18
1.3.143 16 / 18
1.3.142 16 / 18
1.3.141 16 / 18
1.3.140 16 / 18
1.3.139 16 / 18
1.3.138 16 / 18
1.3.137 16 / 18
1.3.136 16 / 18
1.3.135 16 / 18
1.3.134 16 / 18
1.3.133 16 / 18
1.3.132 16 / 18
1.3.131 16 / 18
1.3.130 16 / 18
1.3.129 16 / 18
1.3.128 16 / 18
1.3.127 16 / 18
1.3.126 16 / 18
1.3.125 16 / 18
1.3.124 16 / 18
1.3.123 16 / 18
1.3.122 16 / 18
1.3.121 16 / 18
1.3.120 16 / 18
1.3.119 16 / 18
1.3.118 16 / 18
1.3.117 16 / 18
1.3.116 16 / 18
1.3.115 16 / 18
1.3.114 16 / 18
1.3.113 16 / 18
1.3.112 16 / 18
1.3.111 16 / 18
1.3.110 16 / 18
1.3.109 16 / 18
1.3.108 17 / 18
1.3.107 17 / 18
1.3.106 17 / 18
1.3.105 17 / 18
1.3.104 17 / 18
1.3.103 17 / 18
1.3.102 17 / 18
1.3.101 17 / 18
1.3.100 17 / 18
1.3.99 17 / 18
1.3.98 17 / 18
1.3.97 17 / 18
1.3.96 17 / 18
1.3.95 17 / 18
1.3.94 17 / 18
1.3.93 17 / 18
1.3.92 17 / 18
1.3.91 17 / 18
1.3.90 17 / 18
1.3.89 17 / 18
1.3.88 17 / 18
1.3.87 17 / 18
1.3.86 17 / 18
1.3.85 17 / 18
1.3.84 17 / 18
1.3.83 17 / 18
1.3.82 17 / 18
1.3.81 17 / 18
1.3.80 17 / 18
1.3.79 17 / 18
Showing 100 of 123 Next page →

v1.3.178

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.177

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.176

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.175

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.108

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.107

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.106

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.105

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.104

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.103

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.102

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.101

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.100

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.99

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.98

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.97

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.96

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.95

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.94

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.93

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.92

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.91

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.90

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.88

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.87

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.86

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.85

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.84

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.83

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.82

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.81

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.80

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.79

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.