@salesforce/plugin-org
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:is-wsl | AI (phantom-deps): is-wsl is a legitimate runtime dependency declared in package.json; used for WSL detection in platform-specific behavior. Phantom-dep finding is a false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Salesforce-releases is a well-established, trusted publisher with 1100+ approved packages. Package uses Salesforce's own code-signing mechanism (sfdx publicKeyUrl/signatureUrl) as an alternative integrity mechanism. | ai |
Versions (showing 100 of 207)
| Version | Deps | Published |
|---|---|---|
| 5.11.26 | 12 / 10 | |
| 5.11.25 | 12 / 10 | |
| 5.11.24 | 12 / 10 | |
| 5.11.23 | 12 / 10 | |
| 5.11.22 | 12 / 10 | |
| 5.11.21 | 12 / 10 | |
| 5.11.20 | 12 / 10 | |
| 5.11.19 | 12 / 10 | |
| 5.11.18 | 12 / 10 | |
| 5.11.17 | 12 / 10 | |
| 5.11.16 | 12 / 10 | |
| 5.11.15 | 12 / 10 | |
| 5.11.12 | 12 / 10 | |
| 5.11.11 | 12 / 10 | |
| 5.11.10 | 12 / 10 | |
| 5.11.9 | 12 / 10 | |
| 5.11.8 | 12 / 10 | |
| 5.11.6 | 12 / 10 | |
| 5.11.5 | 12 / 10 | |
| 5.11.4 | 12 / 10 | |
| 5.11.3 | 12 / 10 | |
| 5.11.2 | 12 / 10 | |
| 5.11.1 | 12 / 10 | |
| 5.11.0 | 12 / 10 | |
| 5.10.14 | 12 / 10 | |
| 5.10.13 | 12 / 10 | |
| 5.10.12 | 12 / 10 | |
| 5.10.11 | 12 / 10 | |
| 5.10.10 | 12 / 10 | |
| 5.10.9 | 12 / 10 | |
| 5.10.8 | 12 / 10 | |
| 5.10.7 | 12 / 10 | |
| 5.10.6 | 12 / 10 | |
| 5.10.5 | 12 / 10 | |
| 5.10.4 | 12 / 10 | |
| 5.10.3 | 12 / 10 | |
| 5.10.2 | 12 / 10 | |
| 5.10.1 | 12 / 10 | |
| 5.10.0 | 12 / 10 | |
| 5.9.86 | 12 / 10 | |
| 5.9.85 | 12 / 10 | |
| 5.9.84 | 12 / 10 | |
| 5.9.83 | 12 / 10 | |
| 5.9.82 | 12 / 10 | |
| 5.9.81 | 12 / 10 | |
| 5.9.80 | 12 / 10 | |
| 5.9.79 | 12 / 10 | |
| 5.9.78 | 12 / 10 | |
| 5.9.77 | 12 / 10 | |
| 5.9.76 | 12 / 10 | |
| 5.9.75 | 12 / 10 | |
| 5.9.74 | 12 / 10 | |
| 5.9.73 | 12 / 10 | |
| 5.9.72 | 12 / 10 | |
| 5.9.71 | 12 / 10 | |
| 5.9.70 | 12 / 10 | |
| 5.9.69 | 12 / 10 | |
| 5.9.68 | 12 / 10 | |
| 5.9.67 | 12 / 10 | |
| 5.9.66 | 12 / 10 | |
| 5.9.65 | 12 / 10 | |
| 5.9.64 | 12 / 10 | |
| 5.9.63 | 12 / 10 | |
| 5.9.62 | 12 / 10 | |
| 5.9.61 | 12 / 10 | |
| 5.9.60 | 12 / 10 | |
| 5.9.59 | 12 / 10 | |
| 5.9.58 | 12 / 10 | |
| 5.9.57 | 12 / 10 | |
| 5.9.56 | 12 / 10 | |
| 5.9.55 | 12 / 10 | |
| 5.9.54 | 12 / 10 | |
| 5.9.53 | 12 / 10 | |
| 5.9.52 | 12 / 10 | |
| 5.9.51 | 12 / 10 | |
| 5.9.50 | 12 / 10 | |
| 5.9.48 | 12 / 10 | |
| 5.9.47 | 12 / 10 | |
| 5.9.46 | 12 / 10 | |
| 5.9.45 | 12 / 10 | |
| 5.9.44 | 12 / 10 | |
| 5.9.43 | 12 / 10 | |
| 5.9.42 | 12 / 10 | |
| 5.9.41 | 12 / 10 | |
| 5.9.40 | 12 / 10 | |
| 5.9.39 | 12 / 10 | |
| 5.9.38 | 12 / 10 | |
| 5.9.37 | 12 / 10 | |
| 5.9.36 | 12 / 10 | |
| 5.9.32 | 12 / 10 | |
| 5.9.31 | 12 / 10 | |
| 5.9.30 | 12 / 10 | |
| 5.9.29 | 12 / 10 | |
| 5.9.28 | 12 / 10 | |
| 5.9.27 | 12 / 10 | |
| 5.9.26 | 12 / 10 | |
| 5.9.25 | 12 / 10 | |
| 5.9.24 | 12 / 10 | |
| 5.9.23 | 12 / 10 | |
| 5.9.22 | 12 / 10 |
v5.11.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.