@osdk/create-app
A CLI for bootstrapping OSDK apps on top of popular frameworks
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/esm/esm-SU6MDB7H.js | AI (source-diff): Bundled template-generator content, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-PERM57L7.js | AI (source-diff): Bundled template-generator content, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-ISU4TASH.js | AI (source-diff): Bundled template-generator content, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-CQ65IWOB.js | AI (source-diff): Bundled template-generator content, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-B5R7LTLH.js | AI (source-diff): Bundled template-generator content, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-2T42EZVT.js | AI (source-diff): Bundled template-generator content (long README template strings), not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-QRLMRHCZ.js | AI (source-diff): Bundled template content (handlebars strings), not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-POH2FWFA.js | AI (source-diff): Bundled template content (handlebars strings), not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-KGMIZCJU.js | AI (source-diff): Bundled template content (handlebars strings), not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-FLIEVJDR.js | AI (source-diff): Bundled template content (handlebars strings), not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-4DPBXZEZ.js | AI (source-diff): Bundled template content (handlebars strings), not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-WQOG3NSJ.js | AI (source-diff): Bundled template content (handlebars strings), not obfuscation. | ai | |
| source-diff | obfuscated-file:build/browser/esm-5U6NF4BK.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-GF7PRFTY.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New template packages added to devDeps, expected growth for a scaffolding CLI. | ai | |
| source-diff | obfuscated-file:build/esm/esm-RGNBR5QC.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/browser/esm-RGNBR5QC.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-LYDSFEAA.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/browser/esm-LYDSFEAA.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-L63C2QLW.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/browser/esm-L63C2QLW.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-K3BA3WEF.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/browser/esm-K3BA3WEF.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/browser/esm-GF7PRFTY.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-5U6NF4BK.js | AI (source-diff): Bundled template scaffolding data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-IRYTK2SN.js | AI (source-diff): Same bundled template pattern across create-app templates. | ai | |
| source-diff | obfuscated-file:build/esm/esm-RVZ3BRIG.js | AI (source-diff): Same bundled template pattern across create-app templates. | ai | |
| source-diff | obfuscated-file:build/esm/esm-TYOQYEDZ.js | AI (source-diff): Same bundled template pattern across create-app templates. | ai | |
| source-diff | obfuscated-file:build/esm/esm-V33IJKEW.js | AI (source-diff): Same bundled template pattern across create-app templates. | ai | |
| source-diff | obfuscated-file:build/esm/esm-VZPD4V7P.js | AI (source-diff): Same bundled template pattern across create-app templates. | ai | |
| source-diff | obfuscated-file:build/esm/esm-HPYM2Y43.js | AI (source-diff): Same bundled template pattern across create-app templates. | ai | |
| source-diff | obfuscated-file:build/esm/esm-D3MFKIK5.js | AI (source-diff): Bundled template/README content, not obfuscation; long lines from bundler concatenation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-AJXUW643.js | AI (source-diff): Bundled template scaffold data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-2V4KVWFT.js | AI (source-diff): Bundled template scaffold data (base64/raw file contents), not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-BZOKJHGM.js | AI (source-diff): Bundled template scaffold data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-LAZE43DL.js | AI (source-diff): Bundled template scaffold data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-PIAGFKK6.js | AI (source-diff): Bundled template scaffold data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-SCZI6XCK.js | AI (source-diff): Bundled template scaffold data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-VRP23SG3.js | AI (source-diff): Bundled template scaffold data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-VUWCYTXY.js | AI (source-diff): Bundled template scaffold data, not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/esm/esm-CE2B34NS.js | AI (source-diff): Bundled ESM template file with readable Handlebars content; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/esm/esm-ZNWIB6WR.js | AI (source-diff): Bundled ESM template file with readable Handlebars content; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/esm/esm-X2E7QWV3.js | AI (source-diff): Bundled ESM template file with readable Handlebars content; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/esm/esm-UYHS7HJF.js | AI (source-diff): Bundled ESM template file with readable Handlebars content; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/esm/esm-OAZKICK5.js | AI (source-diff): Bundled ESM template file with readable Handlebars content; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/esm/esm-N4SPMGQ5.js | AI (source-diff): Bundled ESM template file with readable Handlebars content; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/esm/esm-IPIUMRUZ.js | AI (source-diff): Bundled ESM template file with readable Handlebars content; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/esm/esm-EBZWKSQI.js | AI (source-diff): Long lines are base64-encoded template file contents bundled for scaffolding; not obfuscation. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Monorepo build artifact; size drop reflects bundling/optimization, not code replacement. | ai | |
| source-diff | obfuscated-file:build/esm/esm-I53JTF3Q.js | AI (source-diff): Bundled ESM template data; same pattern as other template files in this package. | ai | |
| source-diff | obfuscated-file:build/esm/esm-KEOIKT62.js | AI (source-diff): Bundled ESM template data; same pattern as other template files in this package. | ai | |
| source-diff | obfuscated-file:build/esm/esm-H2N4Q7D7.js | AI (source-diff): Bundled ESM template data (Handlebars .hbs files); long lines are template strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-X4SJX4D4.js | AI (source-diff): Bundled ESM template data; same pattern as other template files in this package. | ai | |
| source-diff | obfuscated-file:build/esm/esm-UNPF6LOC.js | AI (source-diff): Bundled ESM template data; same pattern as other template files in this package. | ai | |
| source-diff | obfuscated-file:build/esm/esm-ROALHSS6.js | AI (source-diff): Bundled ESM template data; same pattern as other template files in this package. | ai | |
| source-diff | obfuscated-file:build/esm/esm-KOAPFR2Q.js | AI (source-diff): Bundled ESM template data; same pattern as other template files in this package. | ai | |
| source-diff | obfuscated-file:build/esm/esm-RBDQWCWM.js | AI (source-diff): Same pattern: bundled app scaffold templates with base64-encoded config files. Not obfuscation. | ai | |
| source-diff | obfuscated-file:build/esm/esm-DZECOYGF.js | AI (source-diff): Bundled template content with long lines from inlined strings; not true obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/esm/esm-Z2RYRPG6.js | AI (source-diff): Base64-encoded template file contents bundled for app scaffolding; not obfuscation. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD monorepo releases routinely publish multiple packages in rapid succession. | ai | |
| source-diff | obfuscated-file:build/esm/esm-XXB7SAYP.js | AI (source-diff): Base64-encoded template file contents bundled for app scaffolding; not obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer follows palantir naming convention; package has SLSA provenance and is part of the official palantir/osdk-ts repo. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): handlebars 4.7.8 is the latest stable release; use in a Palantir CLI scaffolding tool is expected and low-risk. | ai | |
| provenance | no-provenance | AI (provenance): Palantir org package; lack of Sigstore provenance is common and not a risk signal here. | ai | |
| source-diff | obfuscated-file:build/esm/esm-UDGDOKSV.js | AI (source-diff): File contains base64-encoded template assets for app scaffolding; not obfuscation, stable pattern for this package. | ai |
Versions (showing 51 of 75)
| Version | Deps | Published |
|---|---|---|
| 2.48.0 | 5 / 20 | |
| 2.47.0 | 5 / 20 | |
| 2.46.0 | 5 / 20 | |
| 2.45.0 | 5 / 20 | |
| 2.44.0 | 5 / 20 | |
| 2.43.0 | 5 / 20 | |
| 2.42.0 | 5 / 20 | |
| 2.41.0 | 5 / 20 | |
| 2.39.0 | 5 / 20 | |
| 2.38.0 | 5 / 20 | |
| 2.37.0 | 5 / 19 | |
| 2.36.0 | 5 / 19 | |
| 2.35.0 | 5 / 19 | |
| 2.34.0 | 5 / 19 | |
| 2.33.0 | 5 / 19 | |
| 2.32.0 | 5 / 19 | |
| 2.31.0 | 5 / 19 | |
| 2.30.0 | 5 / 19 | |
| 2.29.0 | 5 / 19 | |
| 2.27.0 | 5 / 19 | |
| 2.26.0 | 5 / 19 | |
| 2.25.0 | 5 / 19 | |
| 2.24.0 | 5 / 19 | |
| 2.23.0 | 5 / 19 | |
| 2.22.0 | 5 / 19 | |
| 2.20.0 | 5 / 19 | |
| 2.19.0 | 5 / 19 | |
| 2.17.0 | 5 / 19 | |
| 2.16.0 | 5 / 19 | |
| 2.15.0 | 5 / 19 | |
| 2.14.0 | 5 / 19 | |
| 2.13.0 | 5 / 18 | |
| 2.11.0 | 5 / 18 | |
| 2.10.0 | 5 / 18 | |
| 2.9.0 | 5 / 18 | |
| 2.8.0 | 4 / 19 | |
| 2.7.8 | 4 / 19 | |
| 2.7.7 | 4 / 19 | |
| 2.7.6 | 4 / 19 | |
| 2.7.5 | 4 / 19 | |
| 2.7.4 | 4 / 19 | |
| 2.7.2 | 4 / 19 | |
| 2.7.1 | 4 / 19 | |
| 2.7.0 | 4 / 19 | |
| 2.6.3 | 4 / 19 | |
| 2.6.2 | 4 / 19 | |
| 2.6.1 | 4 / 19 | |
| 2.6.0 | 4 / 19 | |
| 2.5.7 | 4 / 19 | |
| 2.5.6 | 4 / 19 | |
| 2.5.5 | 4 / 19 |
v2.48.0
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.43.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.42.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.41.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.9.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sauravsanj) than the most recent previously approved version (palantir) on 2026-04-13, but sauravsanj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.6
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.5
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.