← Home

@osdk/create-widget

A CLI for bootstrapping OSDK widgets on top of popular frameworks

32
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sauravsanjpalantirericandersonericjeney-palantir

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): High-velocity monorepo with automated CI/CD publishing; rapid publishes are expected and attested via SLSA provenance. ai
maintainer-change maintainer-added AI (maintainer-change): Palantir-scoped username; SLSA provenance confirms CI/CD publish chain; consistent with org team expansion. ai
dependencies unvetted-dep:handlebars AI (dependencies): handlebars 4.7.8 is a pinned, well-known templating library used legitimately in this widget scaffolding tool. ai
phantom-deps phantom-dep:find-up AI (phantom-deps): find-up is a declared runtime dep in package.json; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@osdk/generator-utils AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic false positive for this package. ai

Versions (showing 32 of 32)

Version Deps Published
3.49.0 5 / 12
3.48.0 5 / 12
3.47.0 5 / 12
3.46.0 5 / 12
3.45.0 5 / 12
3.44.0 5 / 12
3.43.0 5 / 12
3.42.0 5 / 12
3.41.0 5 / 12
3.40.0 5 / 12
3.39.0 5 / 12
3.22.0 5 / 12
3.20.0 5 / 12
3.19.0 5 / 12
3.18.0 5 / 12
3.14.0 5 / 12
3.10.0 5 / 11
3.9.0 5 / 11
3.8.0 5 / 11
3.4.8 4 / 12
3.4.5 4 / 12
3.4.3 4 / 12
3.3.4 4 / 12
3.3.3 4 / 12
3.2.5 4 / 12
3.2.4 4 / 12
3.2.3 4 / 12
3.2.0 4 / 12
3.1.2 4 / 12
3.1.1 4 / 12
3.1.0 4 / 12
3.0.0 4 / 12

v3.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.40.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.39.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.