@omnia/tooling
Provide basic stuffs extensible for omnia extension.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): High-volume org package; missing gitHead reflects CI environment change, not a supply-chain risk for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established org package; lack of Sigstore provenance is a process gap, not a security indicator for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established Omnia org package with consistent publisher track record and matching repo; dormancy likely reflects org publishing cadence. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Referenced in config files; stable false positive for this build tooling package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): File-path-based require in a CLI tooling package; standard plugin/config loader pattern across all versions. | ai | |
| phantom-deps | phantom-dep:@omnia/types | AI (phantom-deps): Same-org type-only dependency; phantom detection is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:esbuild-loader | AI (phantom-deps): Referenced in config files; stable false positive for this build tooling package. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): JSON parsing idiom from bundled esbuild-register; not user-controlled arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:globby | AI (phantom-deps): Referenced in config files; stable false positive for this build tooling package. | ai |
Versions (showing 62 of 162)
| Version | Deps | Published |
|---|---|---|
| 7.6.48 | 12 / 0 | |
| 7.6.47 | 12 / 0 | |
| 7.6.46 | 12 / 0 | |
| 7.6.45 | 12 / 0 | |
| 7.6.44 | 12 / 0 | |
| 7.6.43 | 12 / 0 | |
| 7.6.42 | 12 / 0 | |
| 7.6.41 | 12 / 0 | |
| 7.6.40 | 12 / 0 | |
| 7.6.38 | 12 / 0 | |
| 7.6.37 | 12 / 0 | |
| 7.6.36 | 12 / 0 | |
| 7.6.35 | 12 / 0 | |
| 7.6.34 | 12 / 0 | |
| 7.6.33 | 12 / 0 | |
| 7.6.32 | 12 / 0 | |
| 7.6.31 | 12 / 0 | |
| 7.6.30 | 12 / 0 | |
| 7.6.29 | 12 / 0 | |
| 7.6.28 | 12 / 0 | |
| 7.6.27 | 12 / 0 | |
| 7.6.26 | 12 / 0 | |
| 7.6.25 | 12 / 0 | |
| 7.6.24 | 12 / 0 | |
| 7.6.23 | 12 / 0 | |
| 7.6.22 | 12 / 0 | |
| 7.6.21 | 12 / 0 | |
| 7.6.20 | 12 / 0 | |
| 7.6.19 | 12 / 0 | |
| 7.6.18 | 12 / 0 | |
| 7.6.17 | 12 / 0 | |
| 7.6.16 | 12 / 0 | |
| 7.6.15 | 12 / 0 | |
| 7.6.14 | 12 / 0 | |
| 7.6.13 | 12 / 0 | |
| 7.6.12 | 12 / 0 | |
| 7.6.11 | 12 / 0 | |
| 7.6.10 | 12 / 0 | |
| 7.6.9 | 12 / 0 | |
| 7.6.8 | 12 / 0 | |
| 7.6.7 | 12 / 0 | |
| 7.6.6 | 12 / 0 | |
| 7.6.5 | 12 / 0 | |
| 7.6.4 | 12 / 0 | |
| 7.6.3 | 12 / 0 | |
| 7.6.2 | 12 / 0 | |
| 7.6.1 | 12 / 0 | |
| 7.6.0 | 12 / 0 | |
| 7.5.36 | 12 / 0 | |
| 7.5.35 | 12 / 0 | |
| 7.5.34 | 12 / 0 | |
| 7.5.33 | 12 / 0 | |
| 7.5.32 | 12 / 0 | |
| 7.5.31 | 12 / 0 | |
| 7.5.30 | 12 / 0 | |
| 7.5.29 | 12 / 0 | |
| 7.5.28 | 12 / 0 | |
| 7.5.27 | 12 / 0 | |
| 7.5.26 | 12 / 0 | |
| 7.5.25 | 12 / 0 | |
| 7.1.55 | 12 / 0 | |
| 7.1.54 | 12 / 0 |
v7.6.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.5.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.1.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.1.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.