@lynx-js/css-extract-webpack-plugin-canary
This plugin extracts CSS into separate files. It creates a CSS file per JS file which contains CSS.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions CI with SLSA attestation; consistent with official lynx-family org automation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removal consistent with transition to GitHub Actions CI publishing under official org. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by CI/CD migration is a known pattern; SLSA provenance confirms legitimate publish pipeline. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.10.0 | 0 / 8 | |
| 0.9.0 | 0 / 8 | |
| 0.8.0 | 0 / 8 | |
| 0.7.1 | 1 / 9 | |
| 0.7.0 | 1 / 9 | |
| 0.6.5 | 1 / 9 | |
| 0.6.4 | 1 / 9 | |
| 0.6.3 | 1 / 9 | |
| 0.6.2 | 1 / 9 | |
| 0.6.1 | 1 / 9 | |
| 0.6.0 | 1 / 9 | |
| 0.5.4 | 1 / 9 | |
| 0.5.3 | 1 / 9 | |
| 0.5.2 | 1 / 8 | |
| 0.5.1 | 1 / 8 | |
| 0.5.0 | 1 / 9 |
v0.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.