@playcraft/devkit
HTML5 Playable Ads 构建工具,支持多广告渠道打包
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): Build CLI tool; child_process is used to spawn webpack/npm build commands — expected and documented behavior. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads user-supplied builds.config.js at project root — standard config-loading pattern for build tools. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread fires in build command construction context; passing env to child build processes is normal for a build orchestrator. | ai | |
| phantom-deps | phantom-dep:vue | AI (phantom-deps): Peer/build dependency referenced in webpack config templates, not directly imported by the tool. | ai | |
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): Webpack loader dependency referenced in config templates, not directly imported. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped build dependency; loaded by convention via babel-loader. | ai | |
| phantom-deps | phantom-dep:babel-loader | AI (phantom-deps): Webpack loader referenced in config templates, not directly imported. | ai | |
| phantom-deps | phantom-dep:style-loader | AI (phantom-deps): Webpack loader referenced in config templates, not directly imported. | ai | |
| phantom-deps | phantom-dep:esbuild-loader | AI (phantom-deps): Webpack loader referenced in config templates, not directly imported. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Babel preset loaded by convention via babel-loader config, not directly imported. | ai | |
| phantom-deps | phantom-dep:@vue/compiler-sfc | AI (phantom-deps): Vue SFC compiler loaded by vue-loader convention, not directly imported. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 1.0.23 | 30 / 0 | |
| 1.0.22 | 30 / 0 | |
| 1.0.21 | 30 / 0 | |
| 1.0.20 | 30 / 0 | |
| 1.0.19 | 30 / 0 | |
| 1.0.18 | 30 / 0 | |
| 1.0.17 | 30 / 0 | |
| 1.0.16 | 30 / 0 | |
| 1.0.14 | 30 / 0 | |
| 1.0.13 | 30 / 0 | |
| 1.0.12 | 30 / 0 | |
| 1.0.11 | 30 / 0 | |
| 1.0.10 | 30 / 0 | |
| 1.0.9 | 30 / 0 | |
| 1.0.8 | 30 / 0 | |
| 1.0.7 | 29 / 0 | |
| 1.0.6 | 26 / 0 | |
| 1.0.5 | 28 / 0 | |
| 1.0.4 | 25 / 0 | |
| 1.0.3 | 25 / 0 | |
| 1.0.2 | 25 / 0 |
v1.0.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.