@salesforce/plugin-templates
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:yeoman-generator | AI (phantom-deps): Core generator dependency, likely extended via subclassing not detected by import scan. | ai | |
| dependencies | unvetted-dep:@salesforce/templates | AI (dependencies): @salesforce/templates is the core first-party Salesforce template engine; it is the expected primary dependency for this plugin and stable across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Salesforce-releases publisher uses their own signing mechanism (sfdx publicKeyUrl/signatureUrl); lack of Sigstore provenance is acceptable for this established publisher. | ai |
Versions (showing 100 of 206)
| Version | Deps | Published |
|---|---|---|
| 56.20.0 | 3 / 10 | |
| 56.19.5 | 3 / 10 | |
| 56.19.4 | 3 / 10 | |
| 56.19.3 | 3 / 10 | |
| 56.19.2 | 3 / 10 | |
| 56.19.1 | 3 / 10 | |
| 56.19.0 | 3 / 10 | |
| 56.18.18 | 3 / 10 | |
| 56.18.17 | 3 / 10 | |
| 56.18.16 | 3 / 10 | |
| 56.18.15 | 3 / 10 | |
| 56.18.14 | 3 / 10 | |
| 56.18.13 | 3 / 10 | |
| 56.18.12 | 3 / 10 | |
| 56.18.9 | 3 / 10 | |
| 56.18.8 | 3 / 10 | |
| 56.18.7 | 3 / 10 | |
| 56.18.6 | 3 / 10 | |
| 56.18.5 | 3 / 10 | |
| 56.18.4 | 3 / 10 | |
| 56.18.3 | 3 / 10 | |
| 56.18.2 | 3 / 10 | |
| 56.18.1 | 3 / 10 | |
| 56.18.0 | 3 / 10 | |
| 56.17.7 | 3 / 10 | |
| 56.17.6 | 3 / 10 | |
| 56.17.5 | 3 / 10 | |
| 56.17.4 | 3 / 10 | |
| 56.17.3 | 3 / 10 | |
| 56.17.2 | 3 / 10 | |
| 56.17.1 | 3 / 10 | |
| 56.17.0 | 3 / 10 | |
| 56.16.7 | 3 / 10 | |
| 56.16.6 | 3 / 10 | |
| 56.16.5 | 3 / 10 | |
| 56.16.4 | 3 / 10 | |
| 56.16.3 | 3 / 10 | |
| 56.16.2 | 3 / 10 | |
| 56.16.1 | 3 / 10 | |
| 56.16.0 | 3 / 10 | |
| 56.15.7 | 3 / 10 | |
| 56.15.6 | 3 / 10 | |
| 56.15.5 | 3 / 10 | |
| 56.15.4 | 3 / 10 | |
| 56.15.3 | 3 / 10 | |
| 56.15.2 | 3 / 10 | |
| 56.15.1 | 3 / 10 | |
| 56.15.0 | 3 / 10 | |
| 56.14.0 | 3 / 10 | |
| 56.13.4 | 3 / 10 | |
| 56.13.3 | 3 / 10 | |
| 56.13.2 | 3 / 10 | |
| 56.13.1 | 3 / 10 | |
| 56.13.0 | 3 / 10 | |
| 56.12.1 | 3 / 10 | |
| 56.12.0 | 3 / 10 | |
| 56.11.5 | 3 / 10 | |
| 56.11.4 | 3 / 10 | |
| 56.11.3 | 3 / 10 | |
| 56.11.2 | 3 / 10 | |
| 56.11.1 | 3 / 10 | |
| 56.11.0 | 3 / 10 | |
| 56.10.7 | 3 / 10 | |
| 56.10.6 | 3 / 10 | |
| 56.10.5 | 3 / 10 | |
| 56.10.4 | 3 / 10 | |
| 56.10.3 | 3 / 10 | |
| 56.10.2 | 3 / 10 | |
| 56.10.1 | 3 / 10 | |
| 56.10.0 | 3 / 10 | |
| 56.9.3 | 3 / 10 | |
| 56.9.2 | 3 / 10 | |
| 56.9.1 | 3 / 10 | |
| 56.9.0 | 3 / 10 | |
| 56.8.2 | 3 / 10 | |
| 56.8.1 | 3 / 10 | |
| 56.8.0 | 3 / 10 | |
| 56.7.2 | 3 / 10 | |
| 56.7.1 | 3 / 10 | |
| 56.7.0 | 3 / 10 | |
| 56.6.0 | 3 / 10 | |
| 56.5.2 | 3 / 10 | |
| 56.5.1 | 3 / 10 | |
| 56.5.0 | 3 / 10 | |
| 56.4.7 | 3 / 10 | |
| 56.4.6 | 3 / 10 | |
| 56.4.5 | 3 / 10 | |
| 56.4.4 | 3 / 10 | |
| 56.4.3 | 3 / 10 | |
| 56.4.2 | 3 / 10 | |
| 56.4.1 | 3 / 10 | |
| 56.4.0 | 3 / 10 | |
| 56.3.74 | 3 / 10 | |
| 56.3.73 | 3 / 10 | |
| 56.3.72 | 3 / 10 | |
| 56.3.71 | 3 / 10 | |
| 56.3.70 | 3 / 10 | |
| 56.3.69 | 3 / 10 | |
| 56.3.68 | 3 / 10 | |
| 56.3.66 | 3 / 10 |
v56.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.19.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.19.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.19.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.19.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.18.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.18.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.18.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.18.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.18.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.18.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v56.18.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.