@module-federation/esbuild
This package provides an esbuild plugin for Module Federation, enabling you to easily share code between independently built and deployed applications.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher has strong track record; likely legitimate org maintainer rotation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Expected alongside maintainer transition, no other malicious signal. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Consistent with publisher change; trusted account. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-node-resolve | AI (phantom-deps): Framework plugin loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-node-externals | AI (phantom-deps): Build tool plugin; loaded by convention in config. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-commonjs | AI (phantom-deps): Framework plugin loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:rollup | AI (phantom-deps): Build tool; rollup loaded by convention in config, not direct import. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-replace | AI (phantom-deps): Framework plugin loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@module-federation/sdk | AI (phantom-deps): Same org scope; declared as runtime dep, indirect import pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:@hyrious/esbuild-plugin-commonjs | AI (phantom-deps): Referenced in config files as documented; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@chialab/esbuild-plugin-commonjs | AI (phantom-deps): Referenced in config files as documented; not a direct import by design. | ai |
Versions (showing 9 of 110)
| Version | Deps | Published |
|---|---|---|
| 0.0.10 | 14 / 0 | |
| 0.0.9 | 14 / 0 | |
| 0.0.8 | 14 / 0 | |
| 0.0.7 | 14 / 0 | |
| 0.0.6 | 14 / 0 | |
| 0.0.5 | 14 / 0 | |
| 0.0.4 | 14 / 0 | |
| 0.0.3 | 14 / 0 | |
| 0.0.2 | 14 / 0 |
v0.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.