← Home

@salesforce/lds-adapters-cdp-byoc

Used to connect to the CDP BYOC service in core and off-core

17
Versions
SEE LICENSE IN LICENSE.txt
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ire-npm-team-userjimjagsalesforce-releasesjasonschroeder-sfdcmobifylwc-adminsalesforce-admin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): lwc-admin is a high-trust Salesforce org publisher with 1566 approved packages; transition appears to be a legitimate org-level account consolidation. ai
maintainer-change maintainer-added AI (maintainer-change): salesforce-admin addition aligns with org-level account consolidation pattern seen across Salesforce LDS packages. ai
maintainer-change maintainer-removed AI (maintainer-change): Mass removal consistent with Salesforce consolidating individual maintainers to org accounts; no malicious indicators. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by org-account consolidation publish; no code changes indicate legitimate housekeeping rather than takeover. ai
phantom-deps phantom-dep:@salesforce/lds-bindings AI (phantom-deps): Same-org runtime dependency in a Salesforce LDS monorepo; indirect import pattern is stable across versions. ai

Versions (showing 17 of 117)

Version Deps Published
1.360.1 1 / 1
1.360.0 1 / 1
1.359.0 1 / 1
1.358.0 1 / 1
1.357.0 1 / 1
1.356.0 1 / 1
1.355.0 1 / 1
1.354.0 1 / 1
1.353.1 1 / 1
1.353.0 1 / 1
1.352.0 1 / 1
1.351.1 1 / 1
1.351.0 1 / 1
1.350.0 1 / 1
1.349.0 1 / 1
1.348.1 1 / 1
1.348.0 1 / 1

v1.359.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.358.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.357.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.356.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.355.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.354.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.353.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.353.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.352.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.351.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.351.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.350.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.349.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.348.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.348.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.