@salesforce/lds-runtime-mobile
LDS runtime for mobile/hybrid environments.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Large version gap vs last imported sibling; legitimate monorepo refactor. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Expected from multi-version gap and internal dep restructuring. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Internal Salesforce publisher rotation, track record is clean at scale. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Salesforce org-managed package; bulk maintainer roster changes are expected across their LDS monorepo releases. | ai | |
| dependencies | unvetted-dep:@salesforce/lds-luvio-service | AI (dependencies): Co-versioned sibling @salesforce-scoped package; stable pattern. | ai | |
| dependencies | unvetted-dep:@salesforce/lds-luvio-uiapi-records-service | AI (dependencies): Co-versioned sibling @salesforce-scoped package; stable pattern. | ai | |
| dependencies | unvetted-dep:@salesforce/user | AI (dependencies): Internal Salesforce platform dep; stable pattern across all versions of this package. | ai | |
| phantom-deps | phantom-dep:o11y | AI (phantom-deps): Platform observability dep referenced in config only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@salesforce/lds-luvio-uiapi-records-service | AI (phantom-deps): Same-org sibling dep; phantom-dep is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:o11y_schema | AI (phantom-deps): Platform observability schema dep referenced in config only; stable false positive. | ai | |
| phantom-deps | phantom-dep:@salesforce/user | AI (phantom-deps): Same-org Salesforce platform dep; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@salesforce/lds-luvio-service | AI (phantom-deps): Same-org sibling dep; phantom-dep is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@conduit-client/service-provisioner | AI (phantom-deps): Platform-specific conduit dep referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@conduit-client/service-bindings-lwc | AI (phantom-deps): Platform-specific binary package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@conduit-client/service-bindings-imperative | AI (phantom-deps): Platform-specific binary package; stable false positive. | ai |
Versions (showing 51 of 83)
| Version | Deps | Published |
|---|---|---|
| 1.450.0 | 11 / 26 | |
| 1.449.0 | 11 / 26 | |
| 1.448.0 | 11 / 26 | |
| 1.447.1 | 11 / 26 | |
| 1.447.0 | 11 / 26 | |
| 1.446.0 | 11 / 26 | |
| 1.445.0 | 11 / 26 | |
| 1.444.0 | 11 / 27 | |
| 1.443.0 | 11 / 27 | |
| 1.442.0 | 11 / 27 | |
| 1.441.0 | 11 / 27 | |
| 1.440.0 | 11 / 27 | |
| 1.439.0 | 11 / 27 | |
| 1.438.1 | 11 / 27 | |
| 1.438.0 | 11 / 27 | |
| 1.437.0 | 11 / 27 | |
| 1.436.0 | 11 / 27 | |
| 1.435.1 | 11 / 27 | |
| 1.435.0 | 11 / 27 | |
| 1.434.0 | 11 / 27 | |
| 1.433.0 | 11 / 27 | |
| 1.432.0 | 11 / 27 | |
| 1.431.0 | 11 / 27 | |
| 1.430.0 | 11 / 27 | |
| 1.429.0 | 11 / 27 | |
| 1.428.0 | 11 / 27 | |
| 1.427.0 | 11 / 27 | |
| 1.426.1 | 11 / 27 | |
| 1.425.0 | 11 / 27 | |
| 1.424.0 | 11 / 27 | |
| 1.423.0 | 11 / 27 | |
| 1.422.0 | 11 / 27 | |
| 1.421.1 | 11 / 27 | |
| 1.421.0 | 11 / 27 | |
| 1.420.0 | 11 / 27 | |
| 1.419.0 | 11 / 27 | |
| 1.418.0 | 11 / 27 | |
| 1.417.0 | 11 / 27 | |
| 1.416.1 | 11 / 27 | |
| 1.416.0 | 11 / 27 | |
| 1.415.0 | 11 / 27 | |
| 1.414.1 | 11 / 27 | |
| 1.414.0 | 11 / 27 | |
| 1.413.0 | 11 / 27 | |
| 1.412.1 | 11 / 27 | |
| 1.412.0 | 11 / 27 | |
| 1.411.0 | 11 / 27 | |
| 1.410.1 | 11 / 27 | |
| 1.410.0 | 11 / 27 | |
| 1.409.0 | 11 / 27 | |
| 1.405.0 | 9 / 27 |
v1.450.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.449.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.448.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.447.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.447.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.427.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-03-25, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.426.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-03-18, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.425.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-03-12, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.424.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-03-11, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.423.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-03-04, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.422.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-03-04, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.421.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-26, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.421.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-25, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.420.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-18, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.419.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-13, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.418.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-13, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.417.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-11, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.416.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-04, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.416.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-02-04, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.415.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-01-28, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.414.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-01-22, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.414.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-01-22, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.413.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-01-14, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.412.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-01-08, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.412.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2026-01-07, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.411.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2025-12-26, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.410.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2025-12-19, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.410.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2025-12-18, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.409.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lwc-admin) than the most recent previously approved version (dme722) on 2025-12-15, but lwc-admin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.405.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.