@microsoft/sp-build-core-tasks
SharePoint Framework core build tasks
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): microsoft-oss-releases is Microsoft's OSS release automation account; consistent with org-wide publishing patterns. | ai | |
| dependencies | unvetted-dep:@microsoft/gulp-core-build-serve | AI (dependencies): Sibling Microsoft SPFx package; expected dependency for this ecosystem. | ai | |
| dependencies | unvetted-dep:@microsoft/gulp-core-build | AI (dependencies): Sibling Microsoft SPFx package; expected dependency for this ecosystem. | ai | |
| dependencies | unvetted-dep:@microsoft/gulp-core-build-webpack | AI (dependencies): Sibling Microsoft SPFx package; expected dependency for this ecosystem. | ai | |
| license | uncommon-license:https://aka.ms/spfx/license | AI (license): Standard Microsoft SPFx proprietary license URL; consistent across all versions of this package family. | ai | |
| provenance | no-provenance | AI (provenance): Microsoft SPFx monorepo package; provenance not part of their publish pipeline across all versions. | ai | |
| phantom-deps | phantom-dep:colors | AI (phantom-deps): colors is a declared runtime dep used in config context; phantom-dep heuristic is a false positive here. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Legitimate Microsoft SPFx build tooling; short README and no keywords are expected for internal toolchain packages. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): @types/lodash is a type-only dep loaded by convention; stable false positive for this package. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 1.23.2 | 10 / 4 | |
| 1.23.1 | 10 / 4 | |
| 1.23.0 | 10 / 4 | |
| 1.22.2 | 11 / 4 | |
| 1.22.1 | 11 / 4 | |
| 1.22.0 | 11 / 4 | |
| 1.21.1 | 11 / 4 | |
| 1.21.0 | 11 / 4 | |
| 1.20.2 | 11 / 4 |
v1.23.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.