@plone/volto
Volto
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): CI publish variance for large monorepo package, not evidence of tampering. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from new @plone/components and dnd-kit integration in active framework. | ai | |
| dependencies | unvetted-dep:razzle | AI (dependencies): razzle is the standard build tool for Volto, long-standing dependency. | ai | |
| install-behavior | install-behavior:native-compile | AI (install-behavior): 'make patches' is a documented Plone monorepo patch step, not native compilation of fetched code. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Short README is normal for a monorepo subpackage; not spam. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs 'make patches' to apply local patches; standard Volto addon pattern. | ai | |
| source-diff | obfuscated-file:.yarn/releases/yarn-3.2.3.cjs | AI (source-diff): Standard Yarn Berry zero-install bundle; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:.yarn/releases/yarn-3.2.3.cjs | AI (source-diff): Yarn Berry CLI bundle; network+exec is expected for a package manager runtime. | ai | |
| source-diff | encoded-string-file:cypress/support/commands.js | AI (source-diff): Base64-encoded PNG image used as test fixture, not a payload. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are reputable ecosystem packages; consistent with documented v19 migration from react-dnd to @dnd-kit. | ai | |
| dependencies | unvetted-dep:promise-file-reader | AI (dependencies): Long-standing dep in Volto; not newly added in this version. | ai | |
| dependencies | unvetted-dep:react-detect-click-outside | AI (dependencies): Long-standing dep in Volto; not newly added in this version. | ai | |
| dependencies | unvetted-dep:redux-localstorage-simple | AI (dependencies): Long-standing dep in Volto; not newly added in this version. | ai | |
| dependencies | unvetted-dep:react-select-async-paginate | AI (dependencies): Long-standing dep in Volto; not newly added in this version. | ai | |
| dependencies | unvetted-dep:react-anchor-link-smooth-scroll | AI (dependencies): Long-standing dep in Volto; not newly added in this version. | ai | |
| dependencies | unvetted-dep:redux-connect | AI (dependencies): Long-standing dep in Volto; not newly added in this version. | ai | |
| dependencies | unvetted-dep:react-intl-redux | AI (dependencies): Long-standing dep in Volto; not newly added in this version. | ai | |
| phantom-deps | phantom-dep:decorate-component-with-props | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:is-url | AI (phantom-deps): Large framework; deps referenced in config/tooling rather than direct imports is expected. | ai | |
| phantom-deps | phantom-dep:process | AI (phantom-deps): Webpack polyfill declared in package.json; used via config, not direct import. | ai | |
| phantom-deps | phantom-dep:full-icu | AI (phantom-deps): ICU data package used via NODE_ICU_DATA env var in test scripts, not imported. | ai | |
| phantom-deps | phantom-dep:is-hotkey | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:linkify-it | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:redux-actions | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:redux-connect | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:dependency-graph | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:image-extensions | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:slate-hyperscript | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:react-medium-image-zoom | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:react-detect-click-outside | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| phantom-deps | phantom-dep:react-intersection-observer | AI (phantom-deps): Stable large framework; config-referenced dep pattern is expected. | ai | |
| provenance | no-provenance | AI (provenance): Established Plone Foundation package; lack of Sigstore provenance is common and not a risk signal here. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All raw IPs are 127.0.0.1 localhost references in Cypress test config — not network exfiltration. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads process.env only to filter RAZZLE_-prefixed vars for runtime config — expected behavior for this SSR framework. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads user-supplied jest config path from env var — standard build-tool pattern for this package. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 19.2.0 | 93 / 110 | |
| 19.1.6 | 93 / 110 | |
| 19.1.5 | 94 / 110 | |
| 19.1.4 | 94 / 110 | |
| 19.1.3 | 94 / 110 | |
| 19.1.2 | 94 / 110 | |
| 19.1.1 | 94 / 110 | |
| 19.1.0 | 94 / 110 | |
| 19.0.0 | 97 / 108 | |
| 18.35.1 | 93 / 121 | |
| 18.35.0 | 96 / 122 | |
| 18.34.0 | 96 / 122 | |
| 18.33.1 | 96 / 122 | |
| 18.33.0 | 96 / 122 | |
| 18.32.4 | 96 / 124 | |
| 18.32.3 | 97 / 124 | |
| 18.32.2 | 97 / 124 | |
| 18.32.1 | 97 / 123 | |
| 18.32.0 | 97 / 123 | |
| 18.31.0 | 97 / 123 | |
| 18.30.1 | 97 / 123 | |
| 18.30.0 | 96 / 124 | |
| 18.29.1 | 96 / 123 | |
| 18.29.0 | 96 / 123 | |
| 17.23.0 | 177 / 27 | |
| 16.34.2 | 180 / 16 |
v19.2.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sneridagh.
v19.1.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sneridagh.
v19.1.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sneridagh.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.35.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.32.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.32.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.32.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.32.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.29.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v18.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.23.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'postinstall'.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.