← Home

@nativescript/webpack

<p align="center"> <a href="https://nativescript.org"> <img alt="NativeScript" src="https://raw.githubusercontent.com/NativeScript/artwork/main/logo/export/NativeScript_Logo_Dark_Transparent.png" width="100"/> </a> </p>

17
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

rigor789nativescript-bot

Keywords

NativeScriptJavaScriptAndroidiOSTypeScriptwebpack

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): NativeScript org migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern going forward. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by org CI migration; SLSA attestation confirms legitimate publish pipeline. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:lodash.get AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:micromatch AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:raw-loader AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:source-map AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped package loaded by convention in webpack config. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:webpack-cli AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:babel-loader AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:react-refresh AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:postcss-import AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:postcss-loader AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:@vue/compiler-sfc AI (phantom-deps): Framework-scoped package loaded by convention in webpack config. ai
phantom-deps phantom-dep:sass-loader AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai
phantom-deps phantom-dep:ts-loader AI (phantom-deps): Webpack config tool; loaders/plugins referenced in config, not direct imports. ai

Versions (showing 17 of 17)

Version Deps Published
5.0.38 35 / 14
5.0.37 35 / 14
5.0.36 37 / 16
5.0.35 37 / 16
5.0.34 37 / 16
5.0.33 37 / 16
5.0.32 37 / 16
5.0.31 37 / 16
5.0.30 37 / 16
5.0.29 37 / 16
5.0.28 37 / 16
5.0.27 37 / 16
5.0.26 37 / 16
5.0.25 37 / 16
5.0.24 36 / 15
5.0.23 36 / 15
5.0.22 36 / 14

v5.0.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.