@salesforce/mcp-provider-code-analyzer
(For Interal Use Only) Provides MCP Tools for Salesforce Code Analyzer to a MCP Server
17
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
ire-npm-team-userjimjagsalesforce-releasesjasonschroeder-sfdcmobifylwc-adminsalesforce-admin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): salesforce-admin is a Salesforce org account; addition alongside mass removal is consistent with internal consolidation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Mass removal of individual contributors in favor of org account is standard Salesforce package governance. | ai | |
| dependencies | unvetted-dep:@salesforce/code-analyzer-eslint-engine | AI (dependencies): First-party Salesforce code-analyzer engine; consistent with the rest of the dependency set. | ai | |
| provenance | no-provenance | AI (provenance): Established Salesforce org publisher; absence of Sigstore provenance is not a risk signal for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Explicitly marked internal-use package; sparse README and no keywords are expected for internal tooling. | ai |