@oracle/oraclejet
Oracle JavaScript Extension Toolkit (JET) empowers developers by providing a modular open source toolkit based on modern JavaScript, CSS3 and HTML5 design and development principles.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:signals | AI (phantom-deps): OracleJET uses AMD/RequireJS module loading; signals is loaded via runtime config, not ES imports. | ai | |
| phantom-deps | phantom-dep:jquery-ui | AI (phantom-deps): OracleJET uses AMD/RequireJS module loading; jquery-ui is loaded via runtime config, not ES imports. | ai | |
| phantom-deps | phantom-dep:requirejs | AI (phantom-deps): OracleJET uses AMD/RequireJS module loading; requirejs is the loader itself, not imported via ES import. | ai | |
| phantom-deps | phantom-dep:require-css | AI (phantom-deps): OracleJET uses AMD/RequireJS module loading; require-css is a RequireJS plugin loaded at runtime. | ai | |
| phantom-deps | phantom-dep:requirejs-text | AI (phantom-deps): OracleJET uses AMD/RequireJS module loading; requirejs-text is a RequireJS plugin loaded at runtime. | ai | |
| phantom-deps | phantom-dep:@types/signals | AI (phantom-deps): Type-only package loaded by convention; not imported directly in source. | ai | |
| phantom-deps | phantom-dep:@types/geojson | AI (phantom-deps): Type-only package loaded by convention; not imported directly in source. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 20.1.1 | 12 / 0 | |
| 20.1.0 | 12 / 0 | |
| 20.0.5 | 12 / 0 | |
| 20.0.4 | 12 / 0 |
v20.1.1
6 findingsDeclared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20.1.0
6 findingsDeclared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20.0.5
6 findingsDeclared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v20.0.4
6 findingsDeclared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.