@nx/conformance
A Nx plugin which allows users to write and apply rules for your entire workspace that help with consistency, maintainability, reliability and security.
10
Versions
Commercial
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
nrwlownernrwl-jasonjack-nrwlmaxk-nrwljameshenry
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Published by GitHub Actions CI; gitHead absence is a minor CI config change, not a supply-chain indicator for this established package. | ai | |
| semgrep | semgrep:obfuscation-while-true | AI (semgrep): Intentional obfuscation in commercial Nx Powerpack binary for license enforcement; stable pattern across all versions. | ai | |
| phantom-deps | phantom-dep:@nx/key | AI (phantom-deps): Same-org license key dependency; used indirectly through the obfuscated binary. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Used indirectly via bundled/obfuscated code; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Used indirectly via bundled/obfuscated code; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): Known implicit build/bundle dependency; stable false positive for this package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): resolve-rule.js dynamically loads user-defined conformance rules; this is the core plugin-loader pattern for this package. | ai | |
| dependencies | unvetted-dep:@nx/key | AI (dependencies): @nx/key is an internal Nx licensing package; stable dependency for this commercial Nx plugin. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 5.0.9 | 7 / 0 | |
| 5.0.8 | 7 / 0 | |
| 5.0.7 | 7 / 0 | |
| 5.0.6 | 7 / 0 | |
| 5.0.5 | 7 / 0 | |
| 5.0.4 | 7 / 0 | |
| 5.0.3 | 7 / 0 | |
| 5.0.2 | 7 / 0 | |
| 5.0.1 | 7 / 0 | |
| 5.0.0 | 7 / 0 |
v5.0.9
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.