← Home

@jupyterlab/builder

JupyterLab - Extension Builder

18
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

darianblink1073jasongroutfcollonvaljtpiombektaskrassowskijupyterlab-release-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Pattern loads package.json from a caller-supplied path — standard extension builder behavior, not arbitrary module loading. ai
phantom-deps phantom-dep:webpack-cli AI (phantom-deps): Declared as runtime dep for downstream consumers; not directly imported by builder itself. ai
phantom-deps phantom-dep:worker-loader AI (phantom-deps): Declared as runtime dep for downstream consumers; not directly imported by builder itself. ai
phantom-deps phantom-dep:@lumino/widgets AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/commands AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/domutils AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/dragdrop AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/algorithm AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/coreutils AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/messaging AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/signaling AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/disposable AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/properties AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/virtualdom AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:@lumino/application AI (phantom-deps): Peer/runtime dep for JupyterLab extension consumers; stable false positive for this package. ai
phantom-deps phantom-dep:terser-webpack-plugin AI (phantom-deps): Declared as runtime dep for downstream consumers; not directly imported by builder itself. ai
bogus-package bogus-package AI (bogus-package): Well-known JupyterLab project package; README/keyword signals are false positives. ai

Versions (showing 18 of 18)

Version Deps Published
4.5.7 31 / 6
4.5.6 31 / 6
4.5.5 31 / 6
4.5.4 31 / 6
4.5.3 31 / 6
4.5.2 31 / 6
4.5.1 31 / 6
4.5.0 31 / 6
4.4.10 31 / 6
4.4.9 31 / 6
4.4.8 31 / 6
4.4.7 31 / 6
4.4.6 31 / 6
4.4.5 31 / 6
4.4.4 31 / 6
4.4.3 31 / 6
4.4.2 31 / 6
4.3.8 31 / 6

v4.5.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.