@rushstack/rush-sdk
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@pnpm/lockfile.types-900 | AI (dependencies): Aliased official @pnpm/lockfile.types package, not a novel/unvetted dep. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Rush CLI needs child_process for orchestrating builds; expected in bundled lib-shim. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): spawn() used for running build commands, core to Rush's function. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is a documented webpack macro pattern for optional module loading. | ai |
Versions (showing 51 of 83)
| Version | Deps | Published |
|---|---|---|
| 5.177.0 | 7 / 11 | |
| 5.170.1 | 7 / 11 | |
| 5.170.0 | 7 / 11 | |
| 5.169.3 | 7 / 11 | |
| 5.169.2 | 7 / 11 | |
| 5.169.1 | 7 / 11 | |
| 5.169.0 | 7 / 11 | |
| 5.167.0 | 7 / 11 | |
| 5.164.0 | 7 / 11 | |
| 5.163.0 | 7 / 11 | |
| 5.162.0 | 6 / 11 | |
| 5.161.0 | 6 / 11 | |
| 5.160.1 | 6 / 11 | |
| 5.160.0 | 6 / 11 | |
| 5.159.0 | 6 / 11 | |
| 5.158.1 | 6 / 11 | |
| 5.158.0 | 6 / 11 | |
| 5.157.0 | 6 / 11 | |
| 5.156.0 | 6 / 11 | |
| 5.155.1 | 6 / 11 | |
| 5.155.0 | 6 / 10 | |
| 5.154.0 | 6 / 10 | |
| 5.153.2 | 6 / 10 | |
| 5.153.1 | 6 / 10 | |
| 5.153.0 | 6 / 10 | |
| 5.152.0 | 6 / 10 | |
| 5.151.0 | 6 / 10 | |
| 5.150.0 | 6 / 10 | |
| 5.149.1 | 6 / 10 | |
| 5.149.0 | 6 / 10 | |
| 5.148.0 | 6 / 10 | |
| 5.147.2 | 6 / 10 | |
| 5.147.1 | 6 / 10 | |
| 5.147.0 | 6 / 10 | |
| 5.146.0 | 6 / 10 | |
| 5.145.0 | 5 / 10 | |
| 5.144.1 | 6 / 10 | |
| 5.144.0 | 6 / 10 | |
| 5.143.0 | 6 / 10 | |
| 5.142.0 | 6 / 10 | |
| 5.141.4 | 6 / 10 | |
| 5.141.3 | 6 / 10 | |
| 5.141.2 | 6 / 10 | |
| 5.141.1 | 6 / 10 | |
| 5.141.0 | 6 / 10 | |
| 5.140.1 | 6 / 10 | |
| 5.140.0 | 6 / 10 | |
| 5.139.0 | 6 / 10 | |
| 5.138.0 | 6 / 10 | |
| 5.137.0 | 6 / 10 | |
| 5.136.1 | 5 / 10 |
v5.153.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.153.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.153.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.152.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.151.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.150.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.149.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.149.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.148.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.147.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.147.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.147.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.146.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.145.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.144.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.144.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.143.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.142.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.141.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.141.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.141.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.141.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.141.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.140.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.140.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.139.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.138.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.137.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.136.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.