@nx/rspack
The Nx Plugin for Rspack contains executors and generators that support building applications using Rspack.
51
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
nrwlownernrwl-jasonjack-nrwlmaxk-nrwljameshenry
Keywords
MonorepoRspackBundlingModule Federation
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): maxk-nrwl is a rename/continuation of maxkless within the nrwl org; not a takeover. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): maxkless removed as part of username rename to maxk-nrwl; same person/org. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): semver is a well-established, safe utility dependency used across the npm ecosystem. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version bump (22→23) for a large monorepo plugin; new files expected with feature additions. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is used to load user-specified proxy config files — standard pattern for build tools. | ai | |
| phantom-deps | phantom-dep:webpack | AI (phantom-deps): webpack is a declared dep referenced in config/type contexts, not directly imported — stable false positive. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used in module-federation static server executor — expected for a build/dev-server tool. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads only NX_PUBLIC_* env vars for DefinePlugin injection — documented and intentional behavior. | ai | |
| phantom-deps | phantom-dep:sass | AI (phantom-deps): sass is a declared runtime dep used via loader config, not directly imported in JS — stable false positive. | ai |
Versions (showing 51 of 56)
| Version | Deps | Published |
|---|---|---|
| 23.1.0 | 29 / 2 | |
| 23.0.2 | 29 / 2 | |
| 23.0.1 | 29 / 2 | |
| 23.0.0 | 29 / 2 | |
| 22.7.7 | 31 / 2 | |
| 22.7.6 | 31 / 2 | |
| 22.7.5 | 31 / 2 | |
| 22.7.4 | 31 / 2 | |
| 22.7.3 | 31 / 2 | |
| 22.7.2 | 31 / 2 | |
| 22.7.1 | 31 / 2 | |
| 22.7.0 | 31 / 2 | |
| 22.6.5 | 31 / 2 | |
| 22.6.4 | 31 / 2 | |
| 22.6.3 | 31 / 2 | |
| 22.6.2 | 31 / 2 | |
| 22.6.1 | 31 / 2 | |
| 22.6.0 | 31 / 2 | |
| 22.5.4 | 31 / 2 | |
| 22.5.3 | 31 / 2 | |
| 22.5.2 | 31 / 2 | |
| 22.5.1 | 31 / 2 | |
| 22.5.0 | 31 / 2 | |
| 22.4.5 | 31 / 2 | |
| 22.4.4 | 31 / 2 | |
| 22.4.3 | 31 / 2 | |
| 22.4.2 | 31 / 2 | |
| 22.4.1 | 31 / 2 | |
| 22.4.0 | 31 / 2 | |
| 22.3.3 | 31 / 2 | |
| 22.3.2 | 31 / 2 | |
| 22.3.1 | 31 / 2 | |
| 22.3.0 | 31 / 2 | |
| 22.2.7 | 31 / 2 | |
| 22.2.6 | 31 / 2 | |
| 22.2.5 | 31 / 2 | |
| 22.2.4 | 31 / 2 | |
| 22.2.3 | 31 / 2 | |
| 22.2.2 | 31 / 2 | |
| 22.2.1 | 31 / 2 | |
| 22.2.0 | 31 / 2 | |
| 22.1.3 | 31 / 2 | |
| 22.1.2 | 31 / 2 | |
| 22.1.1 | 31 / 2 | |
| 22.1.0 | 31 / 2 | |
| 22.0.4 | 31 / 2 | |
| 22.0.3 | 31 / 2 | |
| 22.0.2 | 31 / 2 | |
| 22.0.1 | 31 / 2 | |
| 22.0.0 | 31 / 2 | |
| 21.6.11 | 31 / 2 |
v23.1.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v23.0.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v22.7.7
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.