@microsoft/teamsfx-core
The TeamsFx Core package implements shared capabilities for Microsoft 365 Agents Toolkit IDE Extensions and the CLI through API contracts defined in the [api](/packages/api).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:swagger2openapi | AI (phantom-deps): Used via config, not direct import; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:office-addin-manifest | AI (phantom-deps): Used via config, not direct import; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@apidevtools/swagger-parser | AI (phantom-deps): Used via config, not direct import; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:md5 | AI (phantom-deps): Config-referenced dep in large legit codebase. | ai | |
| phantom-deps | phantom-dep:@azure/msal-node | AI (phantom-deps): Framework-scoped Azure auth dep loaded by convention; stable FP. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established official Microsoft package (185k dl/wk); metadata gaps are FP, not impersonation. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 3.0.14 | 59 / 74 | |
| 3.0.11 | 58 / 72 | |
| 3.0.10 | 58 / 72 | |
| 3.0.9 | 58 / 72 | |
| 3.0.8 | 58 / 72 | |
| 3.0.7 | 58 / 72 |
v3.0.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.11
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): No repo/homepage, link-dump README, no keywords — hallmarks of a phishing/spam package impersonating Microsoft.) Matched 3 signal(s), weighted score 4: • [S_README_LINKDUMP] README is a link dump (10 URLs) that barely mentions the package — typical of phishing link farms. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.10
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): No repo/homepage, link-dump README, no keywords — hallmarks of a phishing/spam package impersonating Microsoft.) Matched 3 signal(s), weighted score 4: • [S_README_LINKDUMP] README is a link dump (10 URLs) that barely mentions the package — typical of phishing link farms. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.9
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): No repo/homepage, link-dump README, no keywords — hallmarks of a phishing/spam package impersonating Microsoft.) Matched 3 signal(s), weighted score 4: • [S_README_LINKDUMP] README is a link dump (10 URLs) that barely mentions the package — typical of phishing link farms. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.