← Home

@playcraft/devkit

HTML5 Playable Ads 构建工具,支持多广告渠道打包

21
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

homkeraix-playablechenweifang

Keywords

playablescriptsbuilderplayable-adshtml5-adsad-networkad-buildercompressionfflateoptimizationtencentbigoadsmraidvungleapplovingoogle-adsmeta-adsunity-adsironsourcewebpackcli-toolbuild-tool

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): Build CLI tool; child_process is used to spawn webpack/npm build commands — expected and documented behavior. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require loads user-supplied builds.config.js at project root — standard config-loading pattern for build tools. ai
semgrep semgrep:env-spread AI (semgrep): env-spread fires in build command construction context; passing env to child build processes is normal for a build orchestrator. ai
phantom-deps phantom-dep:vue AI (phantom-deps): Peer/build dependency referenced in webpack config templates, not directly imported by the tool. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Webpack loader dependency referenced in config templates, not directly imported. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped build dependency; loaded by convention via babel-loader. ai
phantom-deps phantom-dep:babel-loader AI (phantom-deps): Webpack loader referenced in config templates, not directly imported. ai
phantom-deps phantom-dep:style-loader AI (phantom-deps): Webpack loader referenced in config templates, not directly imported. ai
phantom-deps phantom-dep:esbuild-loader AI (phantom-deps): Webpack loader referenced in config templates, not directly imported. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Babel preset loaded by convention via babel-loader config, not directly imported. ai
phantom-deps phantom-dep:@vue/compiler-sfc AI (phantom-deps): Vue SFC compiler loaded by vue-loader convention, not directly imported. ai

Versions (showing 21 of 21)

Version Deps Published
1.0.23 30 / 0
1.0.22 30 / 0
1.0.21 30 / 0
1.0.20 30 / 0
1.0.19 30 / 0
1.0.18 30 / 0
1.0.17 30 / 0
1.0.16 30 / 0
1.0.14 30 / 0
1.0.13 30 / 0
1.0.12 30 / 0
1.0.11 30 / 0
1.0.10 30 / 0
1.0.9 30 / 0
1.0.8 30 / 0
1.0.7 29 / 0
1.0.6 26 / 0
1.0.5 28 / 0
1.0.4 25 / 0
1.0.3 25 / 0
1.0.2 25 / 0

v1.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.