@omnia/tooling
Provide basic stuffs extensible for omnia extension.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): High-volume org package; missing gitHead reflects CI environment change, not a supply-chain risk for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established org package; lack of Sigstore provenance is a process gap, not a security indicator for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established Omnia org package with consistent publisher track record and matching repo; dormancy likely reflects org publishing cadence. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Referenced in config files; stable false positive for this build tooling package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): File-path-based require in a CLI tooling package; standard plugin/config loader pattern across all versions. | ai | |
| phantom-deps | phantom-dep:@omnia/types | AI (phantom-deps): Same-org type-only dependency; phantom detection is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:esbuild-loader | AI (phantom-deps): Referenced in config files; stable false positive for this build tooling package. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): JSON parsing idiom from bundled esbuild-register; not user-controlled arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:globby | AI (phantom-deps): Referenced in config files; stable false positive for this build tooling package. | ai |
Versions (showing 51 of 64)
| Version | Deps | Published |
|---|---|---|
| 7.11.10 | 12 / 0 | |
| 7.11.9 | 12 / 0 | |
| 7.11.8 | 12 / 0 | |
| 7.11.7 | 12 / 0 | |
| 7.11.6 | 12 / 0 | |
| 7.11.5 | 12 / 0 | |
| 7.11.4 | 12 / 0 | |
| 7.11.3 | 12 / 0 | |
| 7.11.2 | 12 / 0 | |
| 7.11.1 | 12 / 0 | |
| 7.9.43 | 12 / 0 | |
| 7.9.42 | 12 / 0 | |
| 7.9.41 | 12 / 0 | |
| 7.9.40 | 12 / 0 | |
| 7.9.39 | 12 / 0 | |
| 7.9.38 | 12 / 0 | |
| 7.9.37 | 12 / 0 | |
| 7.9.36 | 12 / 0 | |
| 7.9.35 | 12 / 0 | |
| 7.9.34 | 12 / 0 | |
| 7.9.30 | 12 / 0 | |
| 7.9.29 | 12 / 0 | |
| 7.9.28 | 12 / 0 | |
| 7.9.27 | 12 / 0 | |
| 7.9.26 | 12 / 0 | |
| 7.9.25 | 12 / 0 | |
| 7.9.24 | 12 / 0 | |
| 7.9.23 | 12 / 0 | |
| 7.9.22 | 12 / 0 | |
| 7.9.21 | 12 / 0 | |
| 7.9.20 | 12 / 0 | |
| 7.9.19 | 12 / 0 | |
| 7.9.18 | 12 / 0 | |
| 7.9.17 | 12 / 0 | |
| 7.9.14 | 12 / 0 | |
| 7.9.13 | 12 / 0 | |
| 7.9.12 | 12 / 0 | |
| 7.9.11 | 12 / 0 | |
| 7.9.10 | 12 / 0 | |
| 7.9.9 | 12 / 0 | |
| 7.9.7 | 12 / 0 | |
| 7.9.6 | 12 / 0 | |
| 7.9.5 | 12 / 0 | |
| 7.9.4 | 12 / 0 | |
| 7.9.3 | 12 / 0 | |
| 7.9.2 | 12 / 0 | |
| 7.9.1 | 12 / 0 | |
| 7.9.0 | 12 / 0 | |
| 7.8.16 | 12 / 0 | |
| 7.8.15 | 12 / 0 | |
| 7.8.14 | 12 / 0 |
v7.11.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.11.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.11.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.11.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.11.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.11.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.11.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.11.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.11.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.11.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.21
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.19
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.14
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andtii.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.13
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andtii.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.12
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andtii.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.9.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andtii.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.9
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andtii.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.8.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.8.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.8.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.