@salesforce/lds-runtime-bridge
LDS runtime for bridge.app.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): lwc-admin is a trusted Salesforce org publisher with 4798 approved packages; transition from individual to org account is expected. | ai | |
| dependencies | unvetted-dep:@salesforce/user | AI (dependencies): Same @salesforce org scope, pinned stable version; consistent across all package versions. | ai | |
| phantom-deps | phantom-dep:@salesforce/lds-runtime-mobile | AI (phantom-deps): Same-org dep; stable false positive for this bridge package. | ai | |
| phantom-deps | phantom-dep:@salesforce/user | AI (phantom-deps): Same-org dep in a bridge/runtime package; likely re-exported rather than directly imported. | ai | |
| phantom-deps | phantom-dep:@salesforce/lds-instrumentation | AI (phantom-deps): Same-org dep; stable false positive for this bridge package. | ai | |
| phantom-deps | phantom-dep:@salesforce/lds-durable-records | AI (phantom-deps): Same-org dep; stable false positive for this bridge package. | ai | |
| phantom-deps | phantom-dep:@salesforce/lds-bindings | AI (phantom-deps): Same-org dep; stable false positive for this bridge package. | ai |
Versions (showing 51 of 90)
| Version | Deps | Published |
|---|---|---|
| 1.441.0 | 6 / 5 | |
| 1.440.0 | 6 / 5 | |
| 1.439.0 | 6 / 5 | |
| 1.438.1 | 6 / 5 | |
| 1.438.0 | 6 / 5 | |
| 1.437.0 | 6 / 5 | |
| 1.436.0 | 6 / 5 | |
| 1.435.1 | 6 / 5 | |
| 1.435.0 | 6 / 5 | |
| 1.434.0 | 6 / 5 | |
| 1.433.0 | 6 / 5 | |
| 1.432.0 | 6 / 5 | |
| 1.431.0 | 6 / 5 | |
| 1.430.0 | 6 / 5 | |
| 1.429.0 | 6 / 5 | |
| 1.428.0 | 6 / 5 | |
| 1.427.0 | 6 / 5 | |
| 1.426.1 | 6 / 5 | |
| 1.425.0 | 6 / 5 | |
| 1.424.0 | 6 / 5 | |
| 1.423.0 | 6 / 5 | |
| 1.422.0 | 6 / 5 | |
| 1.421.1 | 6 / 5 | |
| 1.421.0 | 6 / 5 | |
| 1.420.0 | 6 / 5 | |
| 1.419.0 | 6 / 5 | |
| 1.418.0 | 6 / 5 | |
| 1.417.0 | 6 / 5 | |
| 1.416.1 | 6 / 5 | |
| 1.415.0 | 6 / 5 | |
| 1.414.1 | 6 / 5 | |
| 1.413.0 | 6 / 5 | |
| 1.412.1 | 6 / 5 | |
| 1.412.0 | 6 / 5 | |
| 1.411.0 | 6 / 5 | |
| 1.410.1 | 6 / 5 | |
| 1.410.0 | 6 / 5 | |
| 1.409.0 | 6 / 5 | |
| 1.405.0 | 6 / 5 | |
| 1.404.0 | 6 / 5 | |
| 1.403.0 | 6 / 5 | |
| 1.402.0 | 6 / 5 | |
| 1.401.0 | 6 / 5 | |
| 1.400.0 | 6 / 5 | |
| 1.399.0 | 6 / 5 | |
| 1.398.0 | 6 / 5 | |
| 1.397.0 | 6 / 5 | |
| 1.396.0 | 6 / 5 | |
| 1.395.0 | 6 / 5 | |
| 1.394.0 | 6 / 5 | |
| 1.393.0 | 6 / 5 |
v1.441.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.440.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.439.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.438.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.438.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.437.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.436.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.435.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.435.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.434.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.433.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.432.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.431.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.430.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.429.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.428.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.427.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.426.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.425.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.424.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.423.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.422.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.421.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.421.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.420.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.419.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.418.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.417.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.416.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.415.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.414.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.413.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.412.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.412.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.411.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.410.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.410.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.409.0
2 findingsThis version was published by a different npm account than previous versions on 2025-12-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.405.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.404.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.403.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.402.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.401.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.400.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.399.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.398.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.397.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.396.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.395.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.394.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.393.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.