@salesforce/plugin-org
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:is-wsl | AI (phantom-deps): is-wsl is a legitimate runtime dependency declared in package.json; used for WSL detection in platform-specific behavior. Phantom-dep finding is a false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Salesforce-releases is a well-established, trusted publisher with 1100+ approved packages. Package uses Salesforce's own code-signing mechanism (sfdx publicKeyUrl/signatureUrl) as an alternative integrity mechanism. | ai |
Versions (showing 51 of 125)
| Version | Deps | Published |
|---|---|---|
| 5.11.6 | 12 / 10 | |
| 5.11.5 | 12 / 10 | |
| 5.11.4 | 12 / 10 | |
| 5.11.3 | 12 / 10 | |
| 5.11.2 | 12 / 10 | |
| 5.11.1 | 12 / 10 | |
| 5.11.0 | 12 / 10 | |
| 5.10.14 | 12 / 10 | |
| 5.10.13 | 12 / 10 | |
| 5.10.12 | 12 / 10 | |
| 5.10.11 | 12 / 10 | |
| 5.10.10 | 12 / 10 | |
| 5.10.9 | 12 / 10 | |
| 5.10.8 | 12 / 10 | |
| 5.10.7 | 12 / 10 | |
| 5.10.6 | 12 / 10 | |
| 5.10.5 | 12 / 10 | |
| 5.10.4 | 12 / 10 | |
| 5.10.3 | 12 / 10 | |
| 5.10.2 | 12 / 10 | |
| 5.10.1 | 12 / 10 | |
| 5.10.0 | 12 / 10 | |
| 5.9.86 | 12 / 10 | |
| 5.9.85 | 12 / 10 | |
| 5.9.84 | 12 / 10 | |
| 5.9.83 | 12 / 10 | |
| 5.9.82 | 12 / 10 | |
| 5.9.81 | 12 / 10 | |
| 5.9.80 | 12 / 10 | |
| 5.9.79 | 12 / 10 | |
| 5.9.78 | 12 / 10 | |
| 5.9.77 | 12 / 10 | |
| 5.9.76 | 12 / 10 | |
| 5.9.75 | 12 / 10 | |
| 5.9.74 | 12 / 10 | |
| 5.9.73 | 12 / 10 | |
| 5.9.72 | 12 / 10 | |
| 5.9.71 | 12 / 10 | |
| 5.9.70 | 12 / 10 | |
| 5.9.69 | 12 / 10 | |
| 5.9.68 | 12 / 10 | |
| 5.9.67 | 12 / 10 | |
| 5.9.66 | 12 / 10 | |
| 5.9.65 | 12 / 10 | |
| 5.9.64 | 12 / 10 | |
| 5.9.63 | 12 / 10 | |
| 5.9.62 | 12 / 10 | |
| 5.9.61 | 12 / 10 | |
| 5.9.60 | 12 / 10 | |
| 5.9.59 | 12 / 10 | |
| 5.9.58 | 12 / 10 |
v5.11.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.86
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.85
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.84
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.83
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.82
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.81
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.80
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.79
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.9.78
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.9.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.9.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.67
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.