@onecx/standalone-shell
This library was generated with [Nx](https://nx.dev).
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate CI/CD migration for this org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer within the same onecx org; consistent with org-level team management. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known Angular build implicit dependency; stable false positive for Angular libraries. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Part of the @onecx scoped library suite; sparse README/keywords are typical for org-internal Angular libs. | ai |
Versions (showing 62 of 62)
| Version | Deps | Published |
|---|---|---|
| 5.57.0 | 1 / 0 | |
| 5.56.0 | 1 / 0 | |
| 5.55.0 | 1 / 0 | |
| 5.54.0 | 1 / 0 | |
| 5.53.1 | 1 / 0 | |
| 5.53.0 | 1 / 0 | |
| 5.52.10 | 1 / 0 | |
| 5.52.9 | 1 / 0 | |
| 5.52.8 | 1 / 0 | |
| 5.52.7 | 1 / 0 | |
| 5.52.6 | 1 / 0 | |
| 5.52.5 | 1 / 0 | |
| 5.52.4 | 1 / 0 | |
| 5.52.3 | 1 / 0 | |
| 5.52.2 | 1 / 0 | |
| 5.52.1 | 1 / 0 | |
| 5.52.0 | 1 / 0 | |
| 5.51.1 | 1 / 0 | |
| 5.51.0 | 1 / 0 | |
| 5.50.0 | 1 / 0 | |
| 5.49.0 | 1 / 0 | |
| 5.48.4 | 1 / 0 | |
| 5.48.3 | 1 / 0 | |
| 5.48.2 | 1 / 0 | |
| 5.48.1 | 1 / 0 | |
| 5.48.0 | 1 / 0 | |
| 5.47.7 | 1 / 0 | |
| 5.47.6 | 1 / 0 | |
| 5.47.5 | 1 / 0 | |
| 5.47.4 | 1 / 0 | |
| 5.47.3 | 1 / 0 | |
| 5.47.2 | 1 / 0 | |
| 5.47.1 | 1 / 0 | |
| 5.47.0 | 1 / 0 | |
| 5.46.1 | 1 / 0 | |
| 5.46.0 | 1 / 0 | |
| 5.45.1 | 1 / 0 | |
| 5.45.0 | 1 / 0 | |
| 5.44.0 | 1 / 0 | |
| 5.43.0 | 1 / 0 | |
| 5.42.0 | 1 / 0 | |
| 5.41.2 | 1 / 0 | |
| 5.41.1 | 1 / 0 | |
| 5.41.0 | 1 / 0 | |
| 5.40.1 | 1 / 0 | |
| 5.40.0 | 1 / 0 | |
| 5.39.0 | 1 / 0 | |
| 5.38.0 | 1 / 0 | |
| 5.37.0 | 1 / 0 | |
| 5.36.0 | 1 / 0 | |
| 5.35.1 | 1 / 0 | |
| 5.35.0 | 1 / 0 | |
| 5.34.5 | 1 / 0 | |
| 5.34.4 | 1 / 0 | |
| 5.34.3 | 1 / 0 | |
| 5.34.2 | 1 / 0 | |
| 5.34.1 | 1 / 0 | |
| 5.34.0 | 1 / 0 | |
| 5.33.0 | 1 / 0 | |
| 5.32.1 | 1 / 0 | |
| 5.32.0 | 1 / 0 | |
| 5.31.0 | 1 / 0 |
v5.57.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.35.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.35.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.34.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.34.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.34.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.34.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.34.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.34.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.33.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.32.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.32.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.31.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.