@opensumi/ide-dev-tool
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): Used in native module rebuild CLI script; expected pattern for IDE dev tooling. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads package.json from a module path in rebuild script; not arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:less | AI (phantom-deps): Build tool dependency referenced in webpack config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Build tool dependency referenced in webpack config; stable false positive. | ai | |
| phantom-deps | phantom-dep:ts-loader | AI (phantom-deps): Webpack loader referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): Webpack loader referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build tool referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:less-loader | AI (phantom-deps): Webpack loader referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:null-loader | AI (phantom-deps): Webpack loader referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:webpack-cli | AI (phantom-deps): CLI tool referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:koa-bodyparser | AI (phantom-deps): Framework dep referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:tsconfig-paths | AI (phantom-deps): Build tool referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:copy-webpack-plugin | AI (phantom-deps): Webpack plugin referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:optimize-css-assets-webpack-plugin | AI (phantom-deps): Webpack plugin referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/koa | AI (phantom-deps): Type definitions; framework-scoped, stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/koa-router | AI (phantom-deps): Type definitions; framework-scoped, stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/koa-bodyparser | AI (phantom-deps): Type definitions; framework-scoped, stable false positive. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 3.9.0 | 25 / 0 | |
| 3.8.2 | 25 / 0 | |
| 3.8.1 | 25 / 0 | |
| 3.8.0 | 25 / 0 | |
| 3.7.1 | 25 / 0 | |
| 3.7.0 | 25 / 0 | |
| 3.6.4 | 25 / 0 | |
| 3.6.3 | 25 / 0 | |
| 3.6.2 | 25 / 0 | |
| 3.6.1 | 25 / 0 | |
| 3.6.0 | 25 / 0 |
v3.8.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.