@salesforce/plugin-agent
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:glob | AI (phantom-deps): glob is a declared runtime dependency used in config/test globs; not a security concern for this package. | ai | |
| provenance | no-provenance | AI (provenance): Salesforce uses its own signing infrastructure (sfdx publicKeyUrl/signatureUrl); Sigstore provenance absence is not a risk for this publisher. | ai |
Versions (showing 100 of 143)
| Version | Deps | Published |
|---|---|---|
| 1.42.1 | 18 / 16 | |
| 1.42.0 | 18 / 16 | |
| 1.41.0 | 18 / 16 | |
| 1.40.5 | 18 / 16 | |
| 1.40.4 | 18 / 16 | |
| 1.40.3 | 18 / 16 | |
| 1.40.2 | 18 / 16 | |
| 1.40.1 | 18 / 16 | |
| 1.40.0 | 18 / 16 | |
| 1.39.1 | 18 / 16 | |
| 1.39.0 | 18 / 16 | |
| 1.38.1 | 18 / 16 | |
| 1.38.0 | 18 / 16 | |
| 1.37.0 | 18 / 16 | |
| 1.36.1 | 18 / 16 | |
| 1.36.0 | 18 / 16 | |
| 1.35.0 | 18 / 16 | |
| 1.34.1 | 18 / 16 | |
| 1.34.0 | 18 / 16 | |
| 1.33.0 | 18 / 16 | |
| 1.32.22 | 18 / 16 | |
| 1.32.21 | 18 / 16 | |
| 1.32.20 | 18 / 16 | |
| 1.32.19 | 18 / 16 | |
| 1.32.18 | 18 / 16 | |
| 1.32.17 | 18 / 16 | |
| 1.32.16 | 18 / 16 | |
| 1.32.15 | 18 / 16 | |
| 1.32.14 | 18 / 16 | |
| 1.32.13 | 18 / 16 | |
| 1.32.12 | 18 / 16 | |
| 1.32.11 | 18 / 16 | |
| 1.32.10 | 18 / 16 | |
| 1.32.9 | 18 / 16 | |
| 1.32.8 | 18 / 16 | |
| 1.32.7 | 18 / 16 | |
| 1.32.6 | 18 / 16 | |
| 1.32.5 | 18 / 16 | |
| 1.32.4 | 18 / 16 | |
| 1.32.3 | 18 / 16 | |
| 1.32.2 | 18 / 16 | |
| 1.32.1 | 18 / 16 | |
| 1.32.0 | 18 / 16 | |
| 1.31.3 | 18 / 16 | |
| 1.31.2 | 18 / 16 | |
| 1.31.1 | 18 / 16 | |
| 1.31.0 | 18 / 16 | |
| 1.30.11 | 18 / 16 | |
| 1.30.10 | 18 / 16 | |
| 1.30.9 | 18 / 16 | |
| 1.30.8 | 18 / 16 | |
| 1.30.7 | 18 / 16 | |
| 1.30.6 | 18 / 16 | |
| 1.30.5 | 18 / 16 | |
| 1.30.4 | 18 / 16 | |
| 1.30.3 | 18 / 16 | |
| 1.30.2 | 18 / 16 | |
| 1.30.1 | 18 / 16 | |
| 1.30.0 | 18 / 16 | |
| 1.29.2 | 18 / 16 | |
| 1.29.1 | 18 / 16 | |
| 1.29.0 | 18 / 16 | |
| 1.28.0 | 18 / 16 | |
| 1.27.7 | 18 / 16 | |
| 1.27.6 | 18 / 16 | |
| 1.27.5 | 18 / 16 | |
| 1.27.4 | 18 / 16 | |
| 1.27.3 | 18 / 16 | |
| 1.27.2 | 18 / 16 | |
| 1.27.1 | 18 / 16 | |
| 1.27.0 | 18 / 16 | |
| 1.26.9 | 18 / 16 | |
| 1.26.8 | 18 / 16 | |
| 1.26.7 | 18 / 16 | |
| 1.26.6 | 18 / 16 | |
| 1.26.5 | 18 / 16 | |
| 1.26.4 | 18 / 16 | |
| 1.26.3 | 18 / 16 | |
| 1.26.2 | 18 / 16 | |
| 1.26.1 | 18 / 16 | |
| 1.26.0 | 18 / 16 | |
| 1.25.3 | 18 / 16 | |
| 1.25.2 | 18 / 16 | |
| 1.25.1 | 18 / 16 | |
| 1.25.0 | 18 / 16 | |
| 1.24.35 | 17 / 16 | |
| 1.24.34 | 17 / 16 | |
| 1.24.33 | 17 / 16 | |
| 1.24.32 | 17 / 16 | |
| 1.24.31 | 17 / 16 | |
| 1.24.30 | 17 / 16 | |
| 1.24.29 | 17 / 16 | |
| 1.24.28 | 17 / 16 | |
| 1.24.27 | 17 / 16 | |
| 1.24.26 | 17 / 16 | |
| 1.24.25 | 17 / 16 | |
| 1.24.24 | 17 / 16 | |
| 1.24.23 | 17 / 16 | |
| 1.24.22 | 17 / 16 | |
| 1.24.21 | 17 / 16 |
v1.42.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.39.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.34.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.33.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.26.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.25.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.24.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.24.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.